Skip to main content
john_whitmore
New Member
December 27, 2018
Question

5.4.9 issues Site to Site VPN to Cisco ASA

  • December 27, 2018
  • 0 replies
  • 2214 views

Hi,

New to certificate based site to site VPN. Tunnel was up in PSK mode. changed authentication to certificate based for regulatory requirements and won't come up. Can i ask the CSR is it ok to generate on firewall 100d i did this. No option to give CN but presumed Fortigate equivalent is certificate subject option are email hostname or IP.

It's not an SSL VPN so no site being access so not sure if this has to be a certain setting.

 

Anyone fill me in on CSR for site to site to Cisco. What common name subject option should i use? Help me understand how the 2 firewalls will verify the Chain and Certificate 

 

Thanks