Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
35-69
Cisco ASDM User Guide
OL-16647-01
Chapter 35 General
Mapping Certificates to IPSec or SSL VPN Connection Profiles
Authentication Mode—Specifies the authentication mode: none, xauth, or hybrid.
none—Specifies no authentication mode.
xauth—Specifies the use of IKE Extended Authentication mode, which provides the capability
of authenticating a user within IKE using TACACS+ or RADIUS.
hybrid—Specifies the use of Hybrid mode, which lets you use digital certificates for security
appliance authentication and a different, legacy method—such as RADIUS, TACACS+ or
SecurID—for remote VPN user authentication. This mode breaks phase 1 of the Internet Key
Exchange (IKE) into the following steps, together called hybrid authentication:
1. The security appliance authenticates to the remote VPN user with standard public key
techniques. This establishes an IKE security association that is unidirectionally authenticated.
2. An extended authentication (xauth) exchange then authenticates the remote VPN user. This
extended authentication can use one of the supported legacy authentication methods.
Note Before setting the authentication type to hybrid, you must configure the authentication server
and create a pre-shared key.
IKE Peer ID Validation—Selects whether IKE peer ID validation is ignored, required, or checked
only if supported by a certificate.
Enable sending certificate chain—Enables or disables sending the entire certificate chain. This
action includes the root certificate and any subordinate CA certificates in the transmission.
ISAKMP Keep Alive—Enables and configures ISAKMP keep alive monitoring.
Disable Keep Alives—Enables or disables ISAKMP keep alives.
Monitor Keep Alives—Enables or disables ISAKMP keep alive monitoring. Selecting this
option makes available the Confidence Interval and Retry Interval fields.
Confidence Interval—Specifies the ISAKMP keep alive confidence interval. This is the number
of seconds the security appliance should allow a peer to idle before beginning keepalive
monitoring. The minimum is 10 seconds; the maximum is 300 seconds. The default for a remote
access group is 300 seconds.
Retry Interval—Specifies number of seconds to wait between ISAKMP keep alive retries. The
default is 2 seconds.
Head end will never initiate keepalive monitoring—Specifies that the central-site security
appliance never initiates keepalive monitoring.
Interface-Specific Authentication Mode—Specifies the authentication mode on a per-interface
basis.
Interface—Lets you select the interface name. The default interfaces are inside and outside, but
if you have configured a different interface name, that name also appears in the list.
Authentication Mode—Lets you select the authentication mode, none, xauth, or hybrid, as
above.
Interface/Authentication Mode table—Shows the interface names and their associated
authentication modes that are selected.
Add—Adds an interface/authentication mode pair selection to the Interface/Authentication
Modes table.
Remove—Removes an interface/authentication mode pair selection from the
Interface/Authentication Modes table.