Pki Configuration Options - Enterasys Security Router X-PeditionTM User Manual

Enterasys security router user's guide
Table of Contents

Advertisement

XSR(aaa-user)#aaa password ThISisMYShaREDsecRET
The following sample configuration creates user Jeremiah in the PromisedLand usergroup, with
DNS, WINS and MPPE encryption, and assigns IP local pool remote_users for remote access:
XSR(config)#aaa group PromisedLand
XSR(aaa-group)#dns server primary 112.16.1.16
XSR(aaa-group)#dns server secondary 112.30.30.20
XSR(aaa-group)#wins server primary 112.16.1.16
XSR(aaa-group)#wins server secondary 112.16.1.13
XSR(aaa-group)#ip pool remote_users
XSR(aaa-group)#pptp encrypt mppe 128
XSR(config)#aaa user Jeremiah
XSR(aaa-user)#password amen
XSR(aaa-user)#group PromisedLand
Note: For generic AAA background information and configurations, refer to
Services"

PKI Configuration Options

The XSR's PKI implementation offers the following CLI commands to:
Identify and configure attributes of Certificate Authorities using the
mode's available commands:
enrollment http-proxy
proxy server.
enrollment url -
this address). Any DNS names must be manually converted and entered as IP addresses.
(Not acme.com but 192.168.1.1).
enrollment retry count
enrollment retry in period
requests.
crl frequency
CRLs.
Collect a CA certificate from a Certificate Authority:
must verify the fingerprint of the CA against provided information as part of this operation to
assure that the CA you access is the CA you expect.
Enroll an IPSec client certificate for your XSR against an authenticated CA:
Immediately update CRL lists by entering
Display various aspects of the crypto configuration using the following
show crypto ca identity
show crypto ca certificates
IPSec client certificates)
show crypto ca crls
Remove individual certificates using the following commands:
on page 16-5 .
specifies SCEP requests to be directed though an intermediate
URL provided to access the CA (consult your CA administrator for
sets the number of retries for pended enrollment requests.
sets the interval between runs of the CRL maintenance task to update
displays all configured CA identities
displays a list of applicable CRLs
sets the interval between retries for pended enrollment
crypto ca authenticate
crypto ca crl request
displays all collected certificates (CA Identities and
VPN Configuration Overview
 "AAA
crypto ca identity
. Note that you
crypto ca enroll
.
show
commands:
XSR User's Guide 14-27
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

X-pedition xsr

Table of Contents