R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
913
[Firewall-pki-entity-en] quit
# Create PKI domain 1, specify the trusted CA as ca server, the URL of the registration server as
http://10.1.2.2/certsrv/mscep/mscep.dll, the authority for certificate request as RA, and the
entity for certificate request as en.
[Firewall] pki domain 1
[Firewall-pki-domain-1] ca identifier ca server
[Firewall-pki-domain-1] certificate request url
http://10.1.2.2/certsrv/mscep/mscep.dll
[Firewall-pki-domain-1] certificate request from ra
[Firewall-pki-domain-1] certificate request entity en
[Firewall-pki-domain-1] quit
# Create the local RSA key pairs.
[Firewall] public-key local create rsa
# Retrieve the CA certificate.
[Firewall] pki retrieval-certificate ca domain 1
# Request a local certificate for Firewall.
[Firewall] pki request-certificate domain 1
# Create an SSL server policy named myssl.
[Firewall] ssl server-policy myssl
# Specify the PKI domain for the SSL server policy as 1.
[Firewall-ssl-server-policy-myssl] pki-domain 1
# Enable client authentication.
[Firewall-ssl-server-policy-myssl] client-verify enable
[Firewall-ssl-server-policy-myssl] quit
# Configure HTTPS service to use SSL server policy myssl.
[Firewall] ip https ssl-server-policy myssl
# Enable HTTPS service.
[Firewall] ip https enable
# Create a local user named usera, and set the password to 123 and service type to telnet.
[Firewall] local-user usera
[Firewall-luser-usera] password simple 123
[Firewall-luser-usera] service-type telnet
2. Configure the HTTPS client (Host)
On Host, launch IE, enter http://10.1.2.2/certsrv in the address bar and request a certificate for
Host as prompted.
3. Verify your configuration
Launch IE on the host, enter https://10.1.1.1 in the address bar, and select the certificate issued
by the CA server. The web interface of Firewall should appear. After entering username usera and
password 123, you should be able to log in to the web interface to access and manage Firewall.
NOTE:
For more information about PKI configuration commands and the public-key local create rsa
command, see
VPN Command Reference
.
For more information about HTTPS, see
Getting Started Guide
.