You can add a digital certificate to the IPsec tunnel using the J-Web configuration editor or the CLI configuration editor. To apply a certificate to an IPsec tunnel:
Table 46: Applying the Local Digital Certificate to an IPsec Tunnel
|
Task |
J-Web Configuration Editor |
CLI Configuration Editor |
|---|---|---|
|
Navigate to the Services level of the configuration hierarchy. Use any unique string for the service set name. |
|
From the [edit] hierarchy level, enter edit services service-set service-set-name |
|
Configure the IPsec VPN options for the services set. Use the CA profile you created in Table 41. |
|
Enter edit services service-set service-set-nameipsec-vpn-options Enter set local-gateway ip-address Enter set trusted-ca ca-profile-ipsec |
|
Configure the IPsec VPN policy. Use the certificate ID you created in Table 44. |
|
Return to the [edit services] hierarchy. Enter set ipsec-vpn ike policy policy-name local-certificate local-verisign |
|
Configure the IPsec VPN proposal. |
|
Enter set ipsec-vpn ike proposal proposal-name authentication-method rsa-signatures |