Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


VPN Concentrator and Certificates

Nov 15,2009 by alperen

image

VPN Concentrator and Certificates

To authenticate using digital certificates, at least one identity certificate and its root certificate must exist on the VPN Concentrator; there could be more. The VPN Concentrator model determines the maximum number of CA and identity certificates allowed.

  • Models 3015–3080—Maximum of 20 root or subordinate CA certificates and 20 identity certificates.

  • Model 3005—No more than six root or subordinate CA certificates and two identity certificates.

In both cases, CA certificate maximums include any supporting registration authority (RA) certificates.

All models of VPN Concentrator can have only one SSL certificate installed.

All digital certificates and private keys are automatically stored in the VPN Concentrator’s Flash memory. Saving them is unnecessary. These stored items aren’t listed and they can’t be displayed using the Administration | File Management menu. All stored private keys are encrypted. Once installed on the VPN Concentrator, the identity certificate appears in the Digital Certificate list for configuring both IPSec LAN-to-LAN connections and IPSec SAs.

Certificate Revocation List (CRL)

The VPN Concentrator can be configured to enable CRL information caching in RAM to speed the process of verifying the revocation status of certificates. When the VPN Concentrator needs to check the revocation status of a certificate, it first checks to see if the CRL exists in cache and that it hasn’t expired. If the CRL has expired, a new one is requested, but if it hasn’t expired, the Concentrator searches the list of revoked serial numbers for the certificate serial number. If a match exists, the authentication fails.

Time Issues

Digital certificates have an expiration date beyond which they’re of no value, much like the driver’s license and passport examples in the paper-based world. Note, because of this expiration date, the VPN Concentrator time and date must be correct and synchronized with network time.

A second time issue is this: certificate enrollment and installation process must be completed within one week of generating the request. Otherwise, the request is deleted.


252 times read

Related news

» Enrolling and Installing Certificates
by alperen posted on Nov 15,2009
» Digital Certificates
by alperen posted on Nov 15,2009
» CAs and Digital Certificates
by alperen posted on Sep 25,2009
» LAN-to-LAN Networks with Digital Certificates
by alperen posted on Dec 31,2009
» Configure the IPSec
by alperen posted on Nov 22,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author