IKE Identity | TNSR Documentation (2024)

In IKE, each party must ensure it is communicating with the correct peer. Oneaspect of this validation is the identity information included in IKE. Eachrouter tells the other its own local identity and they each validate it againstthe stored remote identity. If they do not match, the peer is rejected.

From within config-ipsec-crypto-ike mode, use the identity local andidentity remote commands to configure local and remote identity information.In either case, the identity command enters config-ike-identity mode.

IKE requires both local and remote identities. The local identity is sent to theremote peer during the exchange. The remote identity is used to validate theidentity received from the peer during the exchange.

Note

For site-to-site tunnels the remote ID corresponds to a single peer, whereasfor remote access IPsec there can be many peers.

For remote access IPsec the remote IKE ID is typically %any (with a typeof none) so TNSR can accept connections from clients no matter which IDthey present. Clients vary in how they send the ID, some allow the user toset a specific value, others assume the value (e.g. IP address or EAPusername). Given the lack of uniformity in client behavior, the best practiceis to allow any remote identifier from remote access clients. When using EAP,the client identity is validated as part of authentication, so this does notpresent a significant security concern.

In config-ike-identity, the following commands are available:

type <name>:

Sets the type of identity value. The following types are available:

address:

IPv4 or IPv6 address in the standard notation for either (e.g. 192.0.2.3or 2001:db8:1:2::3)

This is the most common type, with the value set to the address on TNSRused as the local-address for the IPsec tunnel.

dn:

An X.509 distinguished name, such as a certificate subject (e.g./CN=ipsec-auth-1/C=US/ST=Texas/L=Austin/O=Netgate/OU=Engineering)

email:

Email address (e.g. user@example.com).

fqdn:

A fully qualified domain name (e.g. host.example.com)

key-id:

An arbitrary string used as an identity

none:

Automatically interpret the type based on the value

value <text>:

The identity value, in a format corresponding to the chosen type.

Note

The local identity type and value must both be supplied to the administratorof the remote peer so that it can properly identify this endpoint.

Warning

When using site-to-site certificate authentication the type and value of theidentity configuration must match values present in the certificate inorder for the IPsec daemon to locate, match, and validate the correctcertificate entries. In most cases this means using the certificate subject(DN) of each peer, but can also work with Subject Alternative Name (SAN)entries if they are present in the certificate data.

Identity Example

First configure the local identity of this firewall. The identity is an IPaddress, using the same value as the local address of the IPsec tunnel.

tnsr(config-ipsec-crypto-ike)# identity localtnsr(config-ike-identity)# type addresstnsr(config-ike-identity)# value 203.0.113.2tnsr(config-ike-identity)# exit

Next, configure the remote identity. The remote peer has also chosen to use anIP address, the value of which is the remote address used for the IPsec tunnel.

tnsr(config-ipsec-crypto-ike)# identity remotetnsr(config-ike-identity)# type addresstnsr(config-ike-identity)# value 203.0.113.25tnsr(config-ike-identity)# exit
IKE Identity | TNSR Documentation (2024)
Top Articles
This is how much people need to earn to ‘live comfortably’ in California
What are multi-signature wallets and how do they work?
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 6419

Rating: 4 / 5 (71 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.