Client certificate authentication provides enhanced security for remote access VPN users by utilizing digital certificates installed on client devices. You can configure this method for new or existing remote access VPN policies and supports both single certificate and multiple certificate authentication scenarios.
Before you begin
Ensure that client certificates are configured on the endpoints.
Procedure
Step 1 | Choose |
Step 2 | To configure a client certificate for a new remote access VPN policy:
-
Click Add to create a remote access VPN policy.
-
Configure the protocols, devices, and connection profile for the policy.
-
From the Authentication Method drop-down list, choose Client Certificate Only to authenticate each user with a client certificate.
By default, user names are derived from CN and OU fields of the client certificates. To use different fields, configure the Primary and Secondary fields.
-
Select Map specific field to use certificate fields as the username, with the default Primary and Secondary fields set to CN (Common Name) and OU (Organizational Unit).
-
Select Use entire DN (Distinguished Name) as username to automatically retrieve the user identity from the DN. It is a unique identifier used to match users to a connection profile and supports enhanced certificate authentication.
-
From the Primary and Secondary drop-down lists, choose these common values:
-
Configure the required settings for the remote access VPN policy.
-
Click Finish to save the remote access VPN policy.
|
Step 3 | To configure a client certificate for an existing remote access VPN policy:
-
Click the edit icon next to the remote access VPN policy.
-
Click the edit icon next to the connection profile that you want to modify.
-
Click the AAA tab.
-
From the Authentication Method drop-down list, choose Client Certificate Only to authenticate each user with a client certificate.
-
Repeat Step 2d to Step 2f.
-
(Optional) Check the Enable multiple certificate authentication check box to authenticate the client using machine and user certificates.
This option ensures that the device is corporate-issued and also authenticates the user's identity for VPN access. You can choose whether to derive the username from the machine or user certificate.
From the Certificate to choose drop-down list, choose these options:
Note |
If multiple certificate authentication is not enabled, by default, the user certificate (second certificate) is used for authentication.
|
-
Click Save to save the remote access VPN policy.
|