69-79
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter69 General VPN Setup
Mapping Certificates to IPsec or SSL VPN Connection Profiles
ASDM highlights the list after you add it to the table.
Confirm that a list is assigned to the connection profile for which you want to add certificate-based
rules.
ASDM highlights the list after you add it to the table and displays any associated list entries in the
table at the bottom of the pane.
Step2 Use the table at the bottom (Mapping Criteria) to view, add, change or delete entries to the selected list.
Each entry in the list consists of one certificate-based rule. All of the rules in the mapping criteria list
need to match the contents of the certificate for the ASA to choose the associated map index. To assign
a connection if one criterion or another matches, create one list for each matching criterion.
To understand the fields, see the following sections:
Setting a Certificate Matching Policy
Add/Edit Certificate Matching Rule
Add/Edit Certificate Matching Rule Criterion
Setting a Certificate Matching Policy
For IPsec connections, a certificate group matching policy defines the method to use for identifying the
permission groups of certificate users. You can use any or all of these methods:
Fields
Use the configured rules to match a certificate to a group—Lets you use the rules you have defined
under Rules.
Use the certificate OU field to determine the group—Lets you use the organizational unit field to
determine the group to which to match the certificate. This is selected by default.
Use the IKE identity to determine the group—Lets you use the identity you previously defined under
Configuration > VPN > IKE > Global Parameters. The IKE identity can be hostname, IP address,
key ID, or automatic.
Use the peer IP address to determine the group—Lets you use the peer's IP address. This is selected
by default.
Default to group—Lets you select a default group for certificate users that is used when none of the
preceding methods resulted in a match. This is selected by default. Click the default group in the
Default to group list. The group must already exist in the configuration. If the group does not appear
in the list, you must define it by using Configuration > VPN > General > Tunnel Group.
Add/Edit Certificate Matching Rule
Use the Add/Edit Certificate Matching Rule dialog box to assign the name of a list (map) to a
connection profile.
Fields
Map—Choose one of the following:
Existing—Select the name of the map to include the rule.
New—Enter a new map name for a rule.