cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
766
Views
15
Helpful
6
Replies

FTD version 6.3 VPN

malikashraf
Level 1
Level 1

hey folks does anyone know we running FTD 6.3 FMC 6.3 and trying to create a certificate DN for authentication is the possible?

 

Thank you.

1 Accepted Solution

Accepted Solutions

If i remember had a similar issue with FTD 6.3. we tried to make it work but it didnt later we opened a Tac case and the Nice guy at Tac engineer shared a snipping tool with us. 6.3 does not support DN cert authentication.

FTD_INTERNALDOC.PNG

please do not forget to rate.

View solution in original post

6 Replies 6

@malikashraf yes you can use certificate authentication when using FTD/FMC 6.3

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/firepower_threat_defense_site_to_site_vpns.html

 

FYI, you should probably look to upgrade as 6.3 very old and there are considerably more features in newer versions, as well as bug fixes!

 

Hi Rob yes we know its old version and need upgrading. We are working on this with customer. however the requirement is Certificate DN for authentication is required

Are you trying to generate a CSR? Didn't get the exact question.

@Mohammed al Baqariwe need a site-to-site VPN with Cert based but the customer requirement is it has to be on Certificate DN not on CN.

As Rob mentioned, you can use certificates (with associated certificate maps) for site-site VPN authentication. When using a certificate map you can use any field, including DN (Distinguished Name), to match on and authenticate.

https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/reusable_objects.html#id_42800

If i remember had a similar issue with FTD 6.3. we tried to make it work but it didnt later we opened a Tac case and the Nice guy at Tac engineer shared a snipping tool with us. 6.3 does not support DN cert authentication.

FTD_INTERNALDOC.PNG

please do not forget to rate.
Review Cisco Networking for a $25 gift card