IKE Identity | TNSR Documentation (2024)

In IKE, each party must ensure it is communicating with the correct peer. Oneaspect of this validation is the identity information included in IKE. Eachrouter tells the other its own local identity and they each validate it againstthe stored remote identity. If they do not match, the peer is rejected.

From within config-ipsec-crypto-ike mode, use the identity local andidentity remote commands to configure local and remote identity information.In either case, the identity command enters config-ike-identity mode.

IKE requires both local and remote identities. The local identity is sent to theremote peer during the exchange. The remote identity is used to validate theidentity received from the peer during the exchange.

Note

For site-to-site tunnels the remote ID corresponds to a single peer, whereasfor remote access IPsec there can be many peers.

For remote access IPsec the remote IKE ID is typically %any (with a typeof none) so TNSR can accept connections from clients no matter which IDthey present. Clients vary in how they send the ID, some allow the user toset a specific value, others assume the value (e.g. IP address or EAPusername). Given the lack of uniformity in client behavior, the best practiceis to allow any remote identifier from remote access clients. When using EAP,the client identity is validated as part of authentication, so this does notpresent a significant security concern.

In config-ike-identity, the following commands are available:

type <name>:

Sets the type of identity value. The following types are available:

address:

IPv4 or IPv6 address in the standard notation for either (e.g. 192.0.2.3or 2001:db8:1:2::3)

This is the most common type, with the value set to the address on TNSRused as the local-address for the IPsec tunnel.

dn:

An X.509 distinguished name, such as a certificate subject (e.g./CN=ipsec-auth-1/C=US/ST=Texas/L=Austin/O=Netgate/OU=Engineering)

email:

Email address (e.g. [email protected]).

fqdn:

A fully qualified domain name (e.g. host.example.com)

key-id:

An arbitrary string used as an identity

none:

Automatically interpret the type based on the value

value <text>:

The identity value, in a format corresponding to the chosen type.

Note

The local identity type and value must both be supplied to the administratorof the remote peer so that it can properly identify this endpoint.

Warning

When using site-to-site certificate authentication the type and value of theidentity configuration must match values present in the certificate inorder for the IPsec daemon to locate, match, and validate the correctcertificate entries. In most cases this means using the certificate subject(DN) of each peer, but can also work with Subject Alternative Name (SAN)entries if they are present in the certificate data.

Identity Example

First configure the local identity of this firewall. The identity is an IPaddress, using the same value as the local address of the IPsec tunnel.

tnsr(config-ipsec-crypto-ike)# identity localtnsr(config-ike-identity)# type addresstnsr(config-ike-identity)# value 203.0.113.2tnsr(config-ike-identity)# exit

Next, configure the remote identity. The remote peer has also chosen to use anIP address, the value of which is the remote address used for the IPsec tunnel.

tnsr(config-ipsec-crypto-ike)# identity remotetnsr(config-ike-identity)# type addresstnsr(config-ike-identity)# value 203.0.113.25tnsr(config-ike-identity)# exit
IKE Identity | TNSR Documentation (2024)
Top Articles
Special Education - Preschool Education Program (PEP) - Montgomery County Public Schools, Rockville, MD | Montgomery County Public Schools
How to Buy Bitcoin Anonymously with Cash
Foxy Roxxie Coomer
Duralast Gold Cv Axle
Truist Bank Near Here
Is pickleball Betts' next conquest? 'That's my jam'
Chase Bank Operating Hours
Los Angeles Craigs List
Gwdonate Org
Tracking Your Shipments with Maher Terminal
Shreveport Active 911
Kris Carolla Obituary
2016 Ford Fusion Belt Diagram
Gon Deer Forum
Bitlife Tyrone's
Overton Funeral Home Waterloo Iowa
Driving Directions To Bed Bath & Beyond
Clear Fork Progress Book
라이키 유출
Tygodnik Polityka - Polityka.pl
A Biomass Pyramid Of An Ecosystem Is Shown.Tertiary ConsumersSecondary ConsumersPrimary ConsumersProducersWhich
Georgia Cash 3 Midday-Lottery Results & Winning Numbers
Cpt 90677 Reimbursem*nt 2023
Craigslist Ludington Michigan
Pixel Combat Unblocked
Pfcu Chestnut Street
Metro By T Mobile Sign In
Graphic Look Inside Jeffrey Dresser
Litter-Robot 3 Pinch Contact & DFI Kit
2016 Honda Accord Belt Diagram
Does Iherb Accept Ebt
Synchrony Manage Account
Myql Loan Login
Mcgiftcardmall.con
2008 DODGE RAM diesel for sale - Gladstone, OR - craigslist
Paperless Employee/Kiewit Pay Statements
Anhedönia Last Name Origin
Amc.santa Anita
Strange World Showtimes Near Century Stadium 25 And Xd
Port Huron Newspaper
Tacos Diego Hugoton Ks
Phmc.myloancare.com
Dying Light Mother's Day Roof
Das schönste Comeback des Jahres: Warum die Vengaboys nie wieder gehen dürfen
Mlb Hitting Streak Record Holder Crossword Clue
Random Warzone 2 Loadout Generator
Quest Diagnostics Mt Morris Appointment
Julies Freebies Instant Win
Fallout 76 Fox Locations
Goosetown Communications Guilford Ct
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 6419

Rating: 4 / 5 (71 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.