预览加载中,请您耐心等待几秒...
1/8
2/8
3/8
4/8
5/8
6/8
7/8
8/8

在线预览结束,喜欢就下载吧,查找使用更方便

如果您无法下载资料,请参考说明:

1、部分资料下载需要金币,请确保您的账户上有足够的金币

2、已购买过的文档,再次下载不重复扣费

3、资料包下载后请先用软件解压,在使用对应软件打开

我司防火墙配置 aclnumber3003 rule5permitipsource1.1.1.10destination2.2.2.20 # ikeproposal1 authentication-methodrsa-sig dhgroup2 # ikepeerpeer1 exchange-modeaggressive certificatelocal-filenameusg2100_local.cer ike-proposal1 undoversion2 local-id-typeip/name/user-fqdn----------与cisco对接不支持dn认证 remote-nameciscoasa-----------对端的CN remote-address10.0.0.2 nattraversal # ipsecproposalprop1 # ipsecpolicyaaa1isakmp securityacl3003 ike-peerpeer1 proposalprop1 # interfaceEthernet2/0/0 ipaddress10.0.0.1255.255.255.0 ipsecpolicyaaa # # pkientityusg2100 common-nameusg2100 fqdnusg2100.huawei.com ip-address10.0.0.1 emailusg2100@huawei.com # pkidomainusg2100 caidentifierca certificaterequesturlhttp://2.2.10.105/certsrv/mscep/mscep.dll certificaterequestentityusg2100 crlscep certificaterequestpollinginterval2 crlupdate-period1 crlauto-updateenable crlurlhttp://2.2.10.105/certsrv/mscep/mscep.dll # CISCO配置 设备型号 Hardware:ASA5510,256MBRAM,CPUPentium4Celeron1600MHz CiscoAdaptiveSecurityApplianceSoftwareVersion8.4(1) 版本不同将导致配置略有差别。 配置数字证书(离线方式) 创建密钥对; 系统有默认的rsa密钥对,名字为Default-RSA-Key;再次创建将覆盖默认密钥对 ciscoasa(config)#cryptokeygeneratersa WARNING:YouhaveaRSAkeypairalreadydefinednamed<Default-RSA-Key>. Doyoureallywanttoreplacethem?[yes/no]:y Keypairgenerationprocessbegin.Pleasewait... 申请CA证书 创建trustpoint ciscoasa(config)#cryptocatrustpointASDM_TrustPoint1--进入视图 ciscoasa(config-ca-trustpoint)#subject-nameCN=ciscoasa--配置主题 ciscoasa(config-ca-trustpoint)#enrollmentterminal--离线方式,命令行输入整数 离线申请ca证书 ciscoasa(config)#cryptocaauthenticateASDM_TrustPoint1 Enterthebase64encodedCAcertificate. Endwiththeword"quit"onalinebyitself---粘贴base64格式ca证书到命令行 -----BEGINCERTIFICATE----- MIIDajCCAlKgAwIBAgIQC1AATG77kIpMGLCMyhkkjDANBgkqhkiG9w0BAQUFADAR MQ8wDQYDVQQDEwZjYS1kdHQwHhcNMTIwMzA2MTkxNDM0WhcNMTcwMzA2MTkyNDA1 WjARMQ8wDQYDVQQDEwZjYS1kdHQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK AoIBAQCHOE1I0bgaF4WfHZErjaf8Et96xHaZuQxA3DPwO6jIDbXiBdSM4z+OYY+f zz/M1zN/3M1O3az24hEiGnr1hOch4q0Ie466hjV9rB8znbcIN5NAUhBClcAbe+en Fz1uWjy7e6