Cisco PIX 525 Specifikace Strana 253

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 466
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 252
7-11
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 7 Site-to-Site VPN Configuration Examples
Using PIX Firewall with a VeriSign CA
Configuring PIX Firewall 2 with a VeriSign CA
Note The following steps are nearly the same as those in the previous section “Configuring PIX Firewall 1
with a VeriSign CA” for configuring PIX Firewall 2. The differences are in Steps 1 and 2, and Steps 11
to 13, which are specific for the PIX Firewall 2 in this example.
Perform the following steps to configure PIX Firewall 2 for using a VeriSign CA:
Step 1 Define a host name:
hostname SanJose
Step 2 Define the domain name:
domain-name example.com
Step 3 Generate the PIX Firewall RSA key pair:
ca generate rsa key 512
This command is not stored in the configuration.
Step 4 Define VeriSign-related enrollment commands:
ca identity example.com 209.165.202.130
ca configure example.com ca 2 20 crloptional
These commands are stored in the configuration. “2” is the retry period, “20” is the retry count, and the
crloptional option disables CRL checking.
Step 5 Authenticate the CA by obtaining its public key and its certificate:
ca authenticate example.com
This command is not stored in the configuration.
Step 6 Request signed certificates from your CA for your PIX Firewall’s RSA key pair:
ca enroll example.com abcdef
Before entering this command, contact your CA administrator because they will have to authenticate
your PIX
Firewall manually before granting its certificate.
“abcdef” is a challenge password. This can be anything. This command is not stored in the configuration.
Step 7 Verify that the enrollment process was successful using the following command:
show ca certificate
Step 8 Save keys and certificates, and the CA commands (except those indicated) in Flash memory:
ca save all
write memory
Note Use the ca save all command any time you add, change, or delete ca commands in the
configuration. This command is not stored in the configuration.
Zobrazit stránku 252
1 2 ... 248 249 250 251 252 253 254 255 256 257 258 ... 465 466

Komentáře k této Příručce

Žádné komentáře