Configuration Example: Creating an IPsec Profile for Tunnels that Use X.509 Certificates
- Create an IKEv2 authentication proposal.
- In the proposal, define the method to be used for authentication.
- Next, define the PKI trustpoint for the Certificate Authority.
In the example, the server abcd-CA is established as the PKI trustpoint for both certificate signature and verification.
- Configure an IKEv2 profile that specifies a local and remote ID for the CA server,
using IP addresses or distinguished name information.
The example uses distinguished names to identify the server.
device(config)# ikev2 profile with_standalone device(config-ike-profile-with_standalone)# authentication withCert device(config-ike-profile-with_standalone)# local-identifier dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT" device(config-ike-profile-with_standalone)# remote-identifier dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME" device(config-ike-profile-with_standalone)# match-identity local dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT" device(config-ike-profile-with_standalone)# match-identity remote dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME" device(config-ike-profile-with_standalone)# exit !
- Configure an IPsec profile that references the IKEv2 profile you have already configured. The profile can be used when you define parameters for a specific IPsec tunnel to bring the tunnel up using X.509 certificates.
The following example creates the IKEv2 authentication proposal called withcert to use RSA as the authentication method and establishes the PKI trustpoint abcd-CA to sign and verify certificates. The example also configures an IKEv2 profile called with_standalone, which specifies distinguished name identifiers for the device used as Certificate Authority for both verification and signature. The IKEv2 profile is then referenced in one of the configured IPsec profiles, withCert. The IPsec profile can be used to establish an IPsec tunnel using X.509 certificates held by the server configured in the example.
In addition to the X.509 certificate example just defined, the example also configures the profile described previously in the section "Configuring an IKEv2 authentication proposal for use in an IPsec profile." The second proposal and profile can be used to establish a tunnel using a pre-shared key.
device# configure terminal device(config)# ikev2 auth-proposal withCert device(config-ike-auth-proposal-withCert)# method remote rsa device(config-ike-auth-proposal-withCert)# method local rsa device(config-ike-auth-proposal-withCert)# pki-trustpoint abcd-CA sign device(config-ike-auth-proposal-withCert)# pki-trustpoint abcd-CA verify device(config-ike-auth-proposal-withCert)# exit ! device(config)# ikev2 profile with_standalone device(config-ike-profile-with_standalone)# authentication withCert device(config-ike-profile-with_standalone)# local-identifier dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT" device(config-ike-profile-with_standalone)# remote-identifier dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME" device(config-ike-profile-with_standalone)# match-identity local dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT" device(config-ike-profile-with_standalone)# match-identity remote dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME" device(config-ike-profile-with_standalone)# exit ! device(config)# ipsec profile withKey-L2 device(config-ipsec-profile-withKey-L2)# ike-profile withKey-L2 device(config-ipsec-profile-withKey-L2)# exit ! device(config)# ipsec profile withCert device(config-ipsec-profile-withCert)# ike-profile with_standalone !