Тёмный

How to Install an ASA VPN (SSL) Certificate: Cisco ASA Training 101 

soundtraining.net
Подписаться 45 тыс.
Просмотров 167 тыс.
50% 1

www.soundtraini...-cisco-asa-training-101 Learn how to generate a CSR (Certificate Signing Request) to submit to a CA (Certificate Authority) and how to install the signed certificate from the CA. In this Cisco ASA tutorial, IT author-speaker Don R. Crawley shows you the basics of digital certificate management using a combination of the CLI (command line interface) and the GUI (graphical user interface) on a Cisco ASA Security Appliance.

Опубликовано:

 

12 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 47   
@abdumka
@abdumka 27 дней назад
Thanks for the well-documented video-can't believe I'm finding it 11 years after it was posted! Haha!
@soundtraining
@soundtraining 11 лет назад
Apologies for the delayed reply. The FQDN is how the device is identified via its certificate. It doesn't require a DNS A record, but without an A record or an entry in a local hosts file, there would be no point in having the certificate to prove name-based identity. I've never used an IP address with a certificate, but I don't know why it wouldn't work. In fact, there are some CAs that offer that service. Obviously, that would eliminate the need for either an A record or a hosts file entry.
@soundtraining
@soundtraining 11 лет назад
The CA certificate is generated by the device you wish to configure as a certificate authority, such as a Windows Server 2012 computer or a Linux computer. The certificate can either be self-signed or signed by an upstream certificate authority such as Verisign, Comodo, GeoTrust, or any of the many other CAs. If you visit any of the CA websites, you'll find more information about the process.
@soundtraining
@soundtraining 11 лет назад
It's been a while, but I think I got that one from DigiCert. You can get trial certs from lots of providers and most of them should work similarly to what you see in the video.
@tompinkerton8099
@tompinkerton8099 2 года назад
Excellent video! It helped me out immensely.
@professorfrank
@professorfrank 9 месяцев назад
Awesome because the Cisco document is missing the export command
@doncrawley
@doncrawley 9 месяцев назад
I'm glad it was helpful. Thanks for your comment.
@georgiev85
@georgiev85 11 лет назад
So for the "Certificate Subject DN": - does the FQDN need to have an A record in DNS? - can we use an IP instead? I guess I am not sure what the FQDN is used for in this case.
@Breto151
@Breto151 11 лет назад
So just to make sure I have this right you got both certs from Digicert? I have been trying to setup my own Windows 2008 CA to do a similar VPN design. I wasn't sure if the 2nd cert was from Digicert or it was created from something else that I missed.
@malcontentman9820
@malcontentman9820 7 лет назад
When going to install the asa01_soundtraining_crt cert, how was that generated? I think I am missing a step. Many thanks!
@ismailrajaallah1667
@ismailrajaallah1667 11 лет назад
hi can you tell me how to have a ca certificate
@Breto151
@Breto151 11 лет назад
Where did you get the ASA_soundtraining cert from?
@branimirkarajcic7839
@branimirkarajcic7839 11 лет назад
What is the purpose of that default key that is generated? I would think it is because of SSH, but it is not since to get SSH to work it is still needed to generate RSA key.
@mghebremichael
@mghebremichael 8 лет назад
Hello,I am wondering if I can use VPN Digital Certificate on my Both ISP interfaces.... do I need to generate key for each ISP interface?
@cloudwaf3810
@cloudwaf3810 2 года назад
very good,good job
@heraldsison5410
@heraldsison5410 5 лет назад
Hi Sir, i have encountered a problem when installing certificate. i have already generated CSR and comodo already replied to us the certificate, i have also uploaded the CA certificate that comodo gave us. but when i try to install the cert in identity certificate the "Install Button" is greyed out. How can i fix this sir? i really want this to be done within today but i am stucked to this portion, i have attached a screenshot for your reference. Thank you so much, Your reply is much appreciated.
@ishanmishra4386
@ishanmishra4386 9 лет назад
i have received 2 certificated from my CA..intermediate & ssl certificate..which certificate should i install in identity certificate & which one should i install in CA..
@brandonfontaine285
@brandonfontaine285 Год назад
How is this done without ASDM? My CF card cannot hold asa and asdm image
@RaissaMarconConstante
@RaissaMarconConstante 9 лет назад
Hi, excellent video! Could you publish the commands used behind ASDM to install the certificate? I'd really like to know the commands. Thank you!
@soundtraining
@soundtraining 8 лет назад
+Raissa Marcon Constante My apologies for the delay in responding. I just now noticed your question. In the ASDM, there is an option to preview commands. Look under Tools>>Preferences>>General.
@timbatec
@timbatec 10 лет назад
is there any easier way to validate that certificate?
@rohanacharekar92
@rohanacharekar92 8 лет назад
Hi Don thanks a lot for the video. Just wanted to know if you have uploaded the following video on how to associate the certificate with the remote access vpn ??????
@muriloninja
@muriloninja 7 лет назад
Remote Access VPN->Advanced->SSL Settings...then assign it to the Outside interface, it will show up in a list there once you highlight the interface and click edit.
@immenseTie
@immenseTie 7 лет назад
Can I plz get a answer also.....has the next video been released... associate certificate with the remote access vpn
@phuckewe178
@phuckewe178 8 лет назад
I get a message that reads WARNING you already have a RSA key name Default ASA Key. Is this different than the SSL certificate we're generating?
@soundtraining
@soundtraining 8 лет назад
+Phuck Ewe No, the message means you're replacing the default key. You don't actually have to generate a new default key, but I wanted to show the process for generating a key. I just did it that way for the demonstration. Sorry I wasn't more clear about that in the video.
@mudslide135
@mudslide135 10 лет назад
So I generate the key then go to entrust and paste the csr and it keeps giving me the error -null is not a lid country code...what does this mean? Would it be related to not having my home network on a configured domain. Just bough the the asa and am trying to set it up to play around with at home
@xphobe
@xphobe 9 лет назад
+Justin C (K1m0ra) You have to have a valid public DNS domain name associated with the public outside IP of your ASA. You can get one free from dyndns.org, which has the added benefit of being able to track your IP even if you get one via DHCP from your isp, and keeping your domain name registered to it.
@mayankdhingra4086
@mayankdhingra4086 7 лет назад
font size is very small very diffult to see the configuration
@AngyOtt
@AngyOtt 8 лет назад
Do you need a certificate to perform in-class exercise with VPN?
@soundtraining
@soundtraining 8 лет назад
+Paul Kim Older versions of the software did not require a certificate. I couldn't find a way around it in version 9.x. For demonstrations, I either get a trial certificate or set up a certificate server and generate my own. Thanks for your questions.
@AngyOtt
@AngyOtt 8 лет назад
running ASA 832 (can't recall perfectly) so IPSEC/Anyconnect VPN should work just fine, right? Thank you for your answers :D
@minhtruong6935
@minhtruong6935 11 лет назад
love it...thanks
@Asianredneck1000
@Asianredneck1000 9 лет назад
I saw that he saved the self generated as a TXT file not as a CRT. Do I go back and save the file as a crt? I did not see where he saved the asaol.soundtraining.net.crt certificate. Little confused where he got that asao1.soundtraining.crt file from. Was that from digicert? Anyone can help?
@xphobe
@xphobe 9 лет назад
+Tyson Vu Yes, he got it from digicert. Remember, he got two: the intermediate or chain cert file, and also the identity cert file. When he installed each one, he browsed to where he had saved the files. He did mention that you cannot see the extension, but it is .crt.
@rachidfa6376
@rachidfa6376 8 лет назад
I have an ASA 5510 Version 8.2 (5) with the following config Hardware: ASA5510 1024 MB RAM, CPU Pentium 4 Celeron 1600MHz Internal ATA Compact Flash, 256MB my question I want to install Annyconnect vpn with this config. is that it is compatible with the prerequisites to install annyconnect with 256mb flash?Maximum Physical Interfaces : Unlimited Maximum VLANs : 100 Inside Hosts : Unlimited Failover : Active/Active VPN-DES : Enabled VPN-3DES-AES : Enabled Security Contexts : 2 GTP/GPRS : Disabled SSL VPN Peers : 2 Total VPN Peers : 250 Shared License : Disabled AnyConnect for Mobile : Disabled AnyConnect for Cisco VPN Phone : Disabled AnyConnect Essentials : Disabled Advanced Endpoint Assessment : Disabled UC Phone Proxy Sessions : 2 Total UC Proxy Sessions : 2 Botnet Traffic Filter : Disabled thank you
@kelloggfan
@kelloggfan 10 лет назад
following your every move - you make it look easy but for 2 days I am getting the following error: Cannot import certificate - Certificate does no contain device's General Purpose public key for trust point ......ERROR: Failed to parse or verify imported certificate. What could be wrong - I am following exactly every move...??
@soundtraining
@soundtraining 10 лет назад
Which ASA software version are you running?
@kelloggfan
@kelloggfan 10 лет назад
soundtraining.net I am running 8.2(5) ASDM 7.1(6)
@soundtraining
@soundtraining 10 лет назад
William Rossetti William, that's a really old version of the ASA software. The video is based on version 9.11. If you can't upgrade, check out the Cisco documentation at www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/cert_cfg.html
@kelloggfan
@kelloggfan 10 лет назад
so are you saying the older version won't work?
@soundtraining
@soundtraining 10 лет назад
soundtraining.net Not at all. What I'm saying is that the video is based on software version 9.11 and you're working with version 8.25. There are probably differences in the commands and it's been a long time since I've worked with version 8.25, so I don't remember the syntax for that version. That's why I posted the link where you could get the correct syntax for the version you're using.
@raghavanaidu7867
@raghavanaidu7867 8 лет назад
PLZZ EXPLAIN THEORY FIRST
Далее
Understanding Cisco SSL VPN vs IPSec VPN
15:17
Просмотров 229 тыс.
Cisco ASA Certificate Setup for AnyConnect VPN
1:26:53
Просмотров 23 тыс.
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
How SSL certificate works?
6:30
Просмотров 765 тыс.