Quantcast
Channel: SRX Services Gateway topics
Viewing all articles
Browse latest Browse all 3959

SRX Certificate VPN

$
0
0

Hi,

 

Setting up a certificate based site-to-site VPN. 

 

I have -

  1. Created the key-pair.
  2. Generated a CSR.
  3. Had the CSR signed by our Windows CA.
  4. Uploaded the signed certificate to the firewall as a local certificate.
  5. Uploaded the intermediate CA certificate under one ca-profile.
  6. Uploaded the root CA certificate under a different ca-profile.
  7. Uploaded the CA certificate for the external site.

 

I am having IKE v1 authentication errors.

 

In the logs I can see " IP; No public key found".

 

Is there a step I have missed? I noticed on the SRX you cannot upload a certificate chain, so I had to upload the intermediate and root certificates under seperate ca-profiles, do I need to "link" these somehow?

 

Thanks.

 

 


Viewing all articles
Browse latest Browse all 3959

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>