Configuration Example: Creating an IPsec Profile for Tunnels that Use X.509 Certificates

You can use X.509 certificates to establish an IPsec tunnel by configuring the Certificate Authority (CA server) with an IKEv2 profile that is then referenced in an IPsec profile.
The following steps are an example of how to configure an IPsec profile that can be used to invoke a CA server to sign and verify X.509 certificates.
  1. Create an IKEv2 authentication proposal.
    device# configure terminal
    device(config)# ikev2 auth-proposal withCert
    
  2. In the proposal, define the method to be used for authentication.
    device(config-ike-auth-proposal-withCert)# method remote rsa
    device(config-ike-auth-proposal-withCert)# method local rsa
    
  3. Next, define the PKI trustpoint for the Certificate Authority.
    In the example, the server abcd-CA is established as the PKI trustpoint for both certificate signature and verification.
    device(config-ike-auth-proposal-withCert)# pki-trustpoint abcd-CA sign
    device(config-ike-auth-proposal-withCert)# pki-trustpoint abcd-CA verify
    
  4. Configure an IKEv2 profile that specifies a local and remote ID for the CA server, using IP addresses or distinguished name information.
    The example uses distinguished names to identify the server.
    device(config)# ikev2 profile with_standalone 
    device(config-ike-profile-with_standalone)# authentication withCert
    device(config-ike-profile-with_standalone)# local-identifier dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT"
    device(config-ike-profile-with_standalone)# remote-identifier dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME"
    device(config-ike-profile-with_standalone)# match-identity local dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT"
    device(config-ike-profile-with_standalone)# match-identity remote dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME"
    device(config-ike-profile-with_standalone)#  exit
    !
    
  5. Configure an IPsec profile that references the IKEv2 profile you have already configured. The profile can be used when you define parameters for a specific IPsec tunnel to bring the tunnel up using X.509 certificates.
    !
    device(config)# ipsec profile withCert
    device(config-ipsec-profile-withCert)# ike-profile with_standalone
    !
    

The following example creates the IKEv2 authentication proposal called withcert to use RSA as the authentication method and establishes the PKI trustpoint abcd-CA to sign and verify certificates. The example also configures an IKEv2 profile called with_standalone, which specifies distinguished name identifiers for the device used as Certificate Authority for both verification and signature. The IKEv2 profile is then referenced in one of the configured IPsec profiles, withCert. The IPsec profile can be used to establish an IPsec tunnel using X.509 certificates held by the server configured in the example.

In addition to the X.509 certificate example just defined, the example also configures the profile described previously in the section "Configuring an IKEv2 authentication proposal for use in an IPsec profile." The second proposal and profile can be used to establish a tunnel using a pre-shared key.

device# configure terminal
device(config)# ikev2 auth-proposal withCert 
device(config-ike-auth-proposal-withCert)# method remote rsa
device(config-ike-auth-proposal-withCert)# method local rsa
device(config-ike-auth-proposal-withCert)# pki-trustpoint abcd-CA sign
device(config-ike-auth-proposal-withCert)# pki-trustpoint abcd-CA verify
device(config-ike-auth-proposal-withCert)# exit 
!
device(config)# ikev2 profile with_standalone 
device(config-ike-profile-with_standalone)# authentication withCert
device(config-ike-profile-with_standalone)# local-identifier dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT"
device(config-ike-profile-with_standalone)# remote-identifier dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME"
device(config-ike-profile-with_standalone)# match-identity local dn "CN=SPATHA_STANDALONE, ST=CA, C=US, O=SPATHA_SPATHA_ORG_NAME, OU=SPATHA_ALONE_ORG_UNIT"
device(config-ike-profile-with_standalone)# match-identity remote dn "CN=SPATHA48F, ST=CA, C=US, O=SPATHA48F_ORG_NAME"
device(config-ike-profile-with_standalone)#  exit
!
device(config)# ipsec profile withKey-L2
device(config-ipsec-profile-withKey-L2)# ike-profile withKey-L2
device(config-ipsec-profile-withKey-L2)# exit
!
device(config)# ipsec profile withCert
device(config-ipsec-profile-withCert)# ike-profile with_standalone
!