Question about multiple certificates on a SAA

I have a 8.4 (3) ASA5540 running which has AC certificates and identity of installed godaddy.com, identification of the ASA for remote user VPN (are using the client anyconnect.)

There is also a separate certificate server located inside the LAN, which is used for internal purposes.  All the client workstations have this internal server identity certificates.

We would like to be able to continue to use existing godaddy CA/identity certificates to identify the ASA for customers, but we would like to use the internal CA server to identify customers when they start up the session for the SAA AnyConnect.

Is this possible?  I've seen other assignments that you can have more than one green on an interface, but it's a little different - only cert must be used to identify the ASA.  The other is only to identify users.  ASA has allowed me to import the internal CA cert.

If possible, can someone point me to an example config?

Thank you

-Mathew

Hello Matthew,.

Your statement is correct.

You can have the GoDaddy certificate to identify the ASA for the customers, this certificate of identity is that you apply on the external interface.

Then, you can have certificate from another CA (Certificate Authority), in your case and CA internal to identify customers with the SAA. You just need to install root certificates and intermediaries (as applicable) of this new CA in your ASA.

The ASA will verify the identity of the customer against all CA certificates installed in it until there is a validation of the certificate or refuses the connection.

You use certificate authentication in the tunnel used by your customers Anyconnect group:

tunnel-group Anyconnect-group webvpn-attributes

authentication certificate

I hope this helps.

Daniel Moreno

VPN

Tags: Cisco Security

Similar Questions

  • Question about multiple accounts on a single Machine

    Hello

    I have a question about the ability of the creative cloud to be used with multiple users. If we have computers in a lab that are shared machines and each student must buy their own creative cloud for its use. How to set the connection and activation of the account of each student?

    I'm new to creative cloud as well as it has been my understanding as long as its operation...

    Although it is branded as cloud base, the software is downloaded and installed locally

    Students between their Code to activate the application they wish to use...

    This model works if the student is using the software on their own machines, but how does it work if several students with multiple accounts share the same computer?

    If we install the software on the machines for them, is it possible for students to simply enable and disable the software as they go or is this a model that simply does not work.

    Thanks for any help you can provide,

    Hello

    Ask want you many to contact Adobe support for help and information:

    Contact the customer service

    * Be sure to stay connected with your Adobe ID before accessing the link above *.

  • Question about multiple instances of Thunderbird running at the same time

    I read that when you start Thunderbird by clicking on its icon or the shortcut must only load once, even if you click on it several times. It should be just a window of TB. If I click on the shortcut/TB desktop icon, it behaves like that. I can click several times and that a single TB window will open and be active.

    However, if I run the 'quick launch' TB on my windows 8.1 (or no matter what windows) taskbar, I get mulitple TB windows to open, as much as I want. So if I click on TB icon in the quick launch once, I get a single instance of it. Twice, I get two, and etc. In the quick launch any program behaves like that. He starts programs with a single click and launch again and again.

    Only, I click it once and get an instance which is good and how it should be. But this behavior with the quick launch is ok? It must do this not with Thunderbird? Thank you.

    There is usually no advantage by running multiple instances of Thunderbird, unless specifically do you these race with different profiles. In practice, if they are allowed to use the same profile, the first Thunderbird should should acquire the profile and therefore block the others, although this may not become apparent until you try to salvage something, for example, a message, or to change certain settings.

    Your multiple Thunderbird work successfully? They all show the same mixture of accounts, folders and address books? Can all or part of them save and make changes?

    If this is the expected behavior, (i.e. some "typical" windows) I do not like; He does not play well with profile blocking and I think that lead to problems.

  • Question about multiple addresses of peers on a box next to VCS

    If we set up a nearby area in a VCS to point to multiple IP addresses (peer 1, 2 peer, etc.), he will always try first to use peer 1, or alternating?

    We have a secondary path on a remote site with lower WAN bandwidth, so we want only direct calls to address IP 2 peers when Peer 1 is unreachable.

    Nick,

    Area of peers are sought after doing round robin, for example, if we have 2 peers in one area, then the first message will go to the first hand then the next witl message go to the second peer then back to the first peer. Thank you

    Caesar

  • Question about multiple WITHOUT

    We have an ESXi with a Dell MD3200i environment.  It has two controllers with four network interfaces.  They are configured according to best practices of Dell (NICs VLAN / separate subnets):

    A-0: VLAN 200 (10.1.200.11)

    A-1: VLAN 201 (10.1.201.11)

    A-2: VLAN 202 (10.1.202.11)

    A-3: VLAN 203 (10.1.203.11)

    B-0: VLAN 200 (10.1.200.12)

    B-1: VLAN 201 (10.1.201.12)

    B-2: VLAN 202 (10.1.202.12)

    B-3: VLAN 203 (10.1.203.12)

    We acquired another SAN and I want to make it available on the ESXI server.  This particular SAN has two controllers, each with two network interfaces.  I was wondering if I could configure the network adapters to be on the same VLANS / subnets above, like this:

    A-0: VLAN 200 (10.1.200.13)

    A-1: VLAN 201 (10.1.201.13)

    B-0: VLAN 200 (10.1.200.14)

    B-1: VLAN 201 (10.1.201.14)

    Do the above would cause problems with existing SAN iSCSI connections?  (NMP round robin)

    You can have several on the same iSCSI SAN VLAN / subnet, no problem here. This should not cause problems with the existing SAN as long as clearly, you don't try to interconnect them somehow, mix IPs or as vendors are committed to very basic layer 2/3 Networking Basics (i.e. not flooding the network with broadcasts or other), which should be taken for granted at this time.

  • Question about multiple licenses Etester

    Hello

    We currently have a license for etester. We plan to buy additional licenses plus 3. Since etester has a calculation license (one license per PC). currently Etester allows me to store scripts in which the tool is installed. I would like to know how to use the scripts stored in different parts to be stored in a common location. Basically, I want the scripts to be stored in a common location and I should be able to pull up any script from any pc.

    Kindly let me know if this is possible.

    Thank you
    Kaim

    Get all products of OATS and modify the c:\windows\RSW. INI file. Add a new single line entry in the Installation"" section. The new line must be named "SharedDir.

    For example:

    [Install]
    SharedDir = Z:\OATSshare

  • Multiple certificates on SAA

    I need to have different certificates for several types of connections on a SAA.  One certificate for AnyConnect SSL connections and another certificate for SSL connections without client.  I was able to install the two certificates on the SAA.  But, I am unable to assign based on the connection.  When creating a connection type and assign the certificate on the external interface changes.

    Anyone know if I can do this within the ASA?

    No, unfortunately, certificate is bound to the interface of the ASA and you will not be able to have different certificates for different connections/types of SSL VPN.

  • Just a quick question about the appearance of the cluster

    Hello, this is Matthew, just a quick question about the appearance of the cluster

    Is there anyway to rearrange the order of the elements? I know cutting automatic resizing, I could move the items by hand. But if I use the cluster somewhere else, I have to move the items again...

    What I want is of the order of "Mx My Mz Ax Ay Az Temp voltage CS".

    Is there a quicker way to deal with?

    THz so much!

    You can right-click the border of the cluster and choose "arrange control cluster...". "The user interface is not as intuitive as it could be, but it will allow you to reorder items. If you use the cluster in several places, you should make the cluster in a type definition and replace all current uses of the latter with the type definition, so that they all match. They will also update automatically when you make changes to the type definition. Otherwise, you could have a situation where you have multiple groups with the same data types, but with elements in a different order, and your data will be getting a new denominated, when wire you the whole clusters. The data will be in the same order, but given that the item labels are in a different order, you can't get the data you want, when ungroup you by name.

  • Question about cloud connectors

    We try to create a cloud to Eloqua connector. I read the CloudConnectorSampleGuide. I have a few questions about the expected data models and models of general implementation.

    Configuration of the connector of the cloud

    • The CC stores the identification information for each configured CC step Eloquya Eloqua?
      • What are the guidelines for the safe password storage? (I can't store the passwords as dirty one-way-hash that I need the password during execution.  The two-way hash gives an illusion of security but is not better than the plaintext).
    • When the CC is configured, where credentials should take place between the 1st and the 2nd screen? (i.e. as a hidden form field, session cookie cookie/etc.)
    • Eloqua warns the CC when a step is deleted?

    Cloud connector performance

    • What is the average number of steps configured Single that manages the CC?
    • Is it possible for a CC to have 1000 s and unique not configured to query?
    • What are the guidelines for scalability when the connector has to travel 1000 steps configured and survey? The CC requires a worker architecture to manage a large number of configured steps?
    • Are there best practices around the CC recovery hangs
      • For example: CC acquires the State waiting for members and moves to the current State. The CC blocks before the end of the stage. What is the approach suggested for

    recovery of the tasks in the current handling during recovery state? (assuming I have multiple instances of CC of the Eloqua poll). Is the connector of cloud supposed to maintain States of WIP to manage recovery correctly?

    Dmitry, once again, it is entirely to the developer.  When you add contacts to a stage, they will be processed in batches.  There is no limit to how much you add, and since they are left to step up to that dealt with by the connector, how long they sit depends on how long your connector takes to do its job.  Expectations, of course the faster you can deal with the best.

  • I have a question about Adobe TDC license on two devices.

    I have a question about Adobe TDC license on two devices.

    I want to use Adobe of the COMMON tariff on both devices.

    and I heard that it is possible.

    but I need an official document from Adobe.

    You know this part please address the link or documents, please.

    Thank you.

    Best regards.

    Hello

    You can install and activate a license creative cloud on 2 computers, regardless of their operating system. But you must use one at a time, in other words you should not share your license with another user. A license is for a user that can be used in different places as the home and office.  However, creative team of cloud subscription, you can have multiple licenses under a subscription that you can assign to users. You can consult the following links. Answer to your question is mentioned in the first link.

    Adobe Creative Cloud FAQ

    Licensing and terms of use | Adobe

    You can also check the following links for creative team of cloud and management licenses

    Creative cloud for teams. Adobe Creative Cloud for businesses

    Manage your cloud of Adobe Creative for the composition of teams

  • How can I print multiple "certificates of class completion" with a list of students?

    Sorry to ask this in two different forums - I didn't know which was more appropriate.

    that I have no need of instructions of the community - just to remind the appropriate documentation. I want to learn and it work on mine. Just having trouble finding exactly what I need.

    I think it starts by either:

    • importing a text file, or
    • type/paste the list in a PDF form

    Then, the user clicks a button that does the following:

    • Adds a page for each student's name
    • Inserts the name in a form field (with formatting such as the police and alignment)

    My main question at this point is, should the script add new, blank pages with a layer containing the certificate of "substance" or use a stamp that places the certificate image? Or, maybe, the page after the form (or the "Import the names" button) is the certificate of dynamic text field and the script simply duplicate this page for each student, by inserting the name.

    The remaining task is to add a date, but that seems pretty easy - I have not decided who will be by the dynamic/automatic or if the user must type in another area (in the original form).

    I came up with the solution the most impressive in the history of the universe and published a tutorial on my bloggy blog. Check it out!

    Generate multiple certificates using a template PDF and JavaScript | jotascript

  • Question about CPU Ready time %

    Hello Vmware experts.

    Small question about time loan cpu in esxtop. I have a couple of the virtual machine that has been entrusted to 4 vCPU. When you view their stats in esxtop they indicate the highest term of loan from CPU. I was wondering if this figure is the result of adding the ready time of each vCPU? For example, a 4 x vCPU VM with ready time of 10%, does it really mean 2.5% by vCPU? Should I be concerned about ready time of 10%? I read that the multiple assignment of vCPU can unnecessarily cause time CPU ready. How others decide on how many vCPU they must assign to VM here?

    OK, just realised that was more than just a small question... anyway, would be great if someone could make all this a bit clearer for me.

    Thank you

    BTW, my hosts CPU usage to sit at an average of 25%.

    In vSphere they eased the scheduling of multiple vCPU co even more so that only the vCPU who got ahead of the rest is stopped.  It is always advisable to start with a single vCPU and work your way up if necessary.

    In esxtop you can use the e command to extend the CPU statistics.  In several vCPU machines this will let you see the playing time of each CPU (which should add until you have seen earlier) and it will also allow you to see the % used for each processor.  This should allow you to see if the two vCPU are properly used in a box of vCPU multi.   I had also the CSTP % field shows which is the stop of co and will give you an indiciation of how often vCPU on the machine stopped to allow the other CPU to stand.

    Great pdf on the CPU scheduler in vSPhere can be found here http://www.vmware.com/files/pdf/perf-vsphere-cpu_scheduler.pdf

    If you have found this device or any other useful post please consider the use of buttons useful/correct to award points

    Twitter: http://twitter.com/mittim12

  • Question about the Oracle database resource management

    Good evening
    I have a question about Oracle database Resource Management (DRM) for Oracle Database 10 g. I had an incident which, in a development/UAT environment (different instances, same box, don't ask), a developer wrote a wrong SQL statement that consumed 99% of the CPU. Currently, there is no limit of resources on two cases of db, and the developers don't want limits. However, my manager wants a method to prevent something like this does not happen. If I use the Oracle database resources management, create a consumer group (called "DevEnv") at 40% CPU usage, what will happen if a user of DevEnv runs a bad SQL statement that normally consumes 90% CPU again? Anyone would take a different approach? Thank you.

    Sincerely,
    Sho Fukamachi

    782718 wrote:
    If users in the case of "db_uat" use 60% CPU would be users who belongs to DevEnv pending 'db_test' cannot be used more than 40% CPU, so their queries become slower at their end? I would like to know if this behavior works the same in an environment of multiple instances. Thank you.

    Yes, because the available processor would be 40%, they use more, while.

  • MAA - RAEVEN & DataGuard conceptual question about Photo (10.2 doc)

    Hello experts,

    I have question about the figure:
    'D.1.2 putting into place of a primary of multiple instances with a multi-Instance standby'
    http://download.Oracle.com/docs/CD/B19306_01/server.102/b14239/IMG/rac_arch.gif

    page http://download.oracle.com/docs/cd/B19306_01/server.102/b14239/rac_support.htm

    Detailed explanation is provideded here:
    http://download.Oracle.com/docs/CD/B19306_01/server.102/b14239/img_text/rac_arch.htm

    It is said:
    «This illustration shows a primary database archiving online redo logs to a database, multi-instance multi-instance ensures in a Real Application Clusters environment.» In this configuration, there are two instances of primary database: has the instance primary and primary Instance B. There are also two instances of sleep: standby receiving Instance C and standby recovery Instance D. The definition and purpose to receive the bodies and recovery is described in the text that follows this illustration. Each primary instance uses a LGWR to write again online newspapers and recovery logs archived local processes on the primary instance. In addition, the process LGWR on the primary Instance a sends its changes over an Oracle Net network to the RFS in First Instance B process and to the RFS process on Standby receiving Instance C. primary Instance B sends its changes over an Oracle Net network to the RFS on Standby Recovery Instance D process. The RFS process on each standby instance written in local newspapers do sleep. This figure also shows how the process ARCn on Standby receiving Instance C sends its changes over an Oracle Net network to the process on Standby Recovery Instance D RFS. The process on Standby Recovery Instance D ARCn also archives its changes in newspapers local archived redo. »

    Question I would like to ask because I'd like to better understand the Internals:
    (1) why it is written that LGWR writes Archives newspapers and not ARCH process? Is this some sort of error doc. ?
    (2) what is the reason that LGWR sends redo changes made to the FIU to the instance of the same (primary) cluster? What is the purpose? What happens if it has many nodes in the primary? This means that this instance would be multicast it to each of them in this way?
    (3) on the backup site: MRP is located on the D instance in this scenario? (1 single standby instance is applying the data but several can recive redo and write it to the SRls)?

    (1) why it is written that LGWR writes Archives newspapers and not ARCH process? Is this some sort of error doc. ?
    Yes, it seems that this picture has been simplified, and it does not show the level of appropriate detail.
    (2) what is the reason that LGWR sends redo changes made to the FIU to the instance of the same (primary) cluster? What is the purpose? What happens if it has many nodes in the primary? This means that this instance would be multicast it to each of them in this way?
    This shows what we call "cross instance archiving". If you enable this, one storing data on multiple nodes. So if you are in a cluster, and archive locally, if this node dies, so how you get that archive the data to retrieve, put the archives in several places gives you extra security for those who are paranoid. I think that it was more useful in the days where Oracle shipped just archiving logs, now that lgwr writes to the remote node, you are less likely to need it.
    (3) on the backup site: MRP is located on the D instance in this scenario? (1 single standby instance is applying the data but several can recive redo and write it to the SRls)?
    Yes one instance applies to the remake.

  • Cannot see the details of the certificate when you try to display more information about the certificate. Need a fix as soon as possible!

    When you click on the padlock to the left of the URL > right arrow > and then click more information > to view details about the certificate Details page > view certificate, I see nothing and nothing shows me the certificate. I need this job to be able to view Details of the certificate and encryption information pages

    Hmm, you are using the all-in - One Sidebar extension? It has a compatibility issue with the Page Info dialog box in Firefox 42. See: FF42 - view Page Info - media tab is missing.

Maybe you are looking for

  • 300 GB in apps?

    Hello, I am new to this operating system and do not know if it is correct. in 300 GB showing system preferences applications are increasing, but see the HDD information shows me any other information.

  • iMac (27-inch, late 2012) shut down

    Hello I contacted AppleCare 4 times now with the same defect and have nowhere fast, I can't dispense with the pillar to post so decided to post my problem on here hoping someone may be able to shed some light? MY iMac has recently begun stop intermit

  • Satellite Pro - need drivers for XP

    I'm looking to rebuild a P4532 satellite, which no longer has his records so I'm looking for some Windows XP drivers for it but I can't find them anywhere - I can't find the real portable anywhere. It is said about it by Satellite P4532 and the model

  • I can't get into programs in my control panel; He advises lack file "C:\Windows\system32\rundll32.exe. What happened, please!

    Also, once in addition to not enter the programs on the Control Panel, it says corrupted boot file, a copy of the original.  I'm sorry, I'm not very computer savy.  Could someone please inform me of what has past.  I am an older woman and need help f

  • HP Pavilion G7 - 1316dx reset password Adninistrator?

    I turned on the lap top yesterday and he asked my administrator password or power on password. I entered what I thought it would be, and after 3 times, it disables the system. It gives a code< 55627001="">. Does anyone have an idea on how to reset. A