<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://hurlster.com/wiki/index.php?action=history&amp;feed=atom&amp;title=IOS_VPN</id>
	<title>IOS VPN - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://hurlster.com/wiki/index.php?action=history&amp;feed=atom&amp;title=IOS_VPN"/>
	<link rel="alternate" type="text/html" href="https://hurlster.com/wiki/index.php?title=IOS_VPN&amp;action=history"/>
	<updated>2026-10-10T20:33:03Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://hurlster.com/wiki/index.php?title=IOS_VPN&amp;diff=2547&amp;oldid=prev</id>
		<title>Gqwill69: /* iPhone to IOS VPN (PPTP) */</title>
		<link rel="alternate" type="text/html" href="https://hurlster.com/wiki/index.php?title=IOS_VPN&amp;diff=2547&amp;oldid=prev"/>
		<updated>2013-03-27T17:37:13Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;iPhone to IOS VPN (PPTP)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094ecd.shtml|Configuring IPSec Network Security]&amp;lt;br /&amp;gt;&lt;br /&gt;
== IPsec Site to Site ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Cisco IOS: 2811 to 837 via PAT/NAT router&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;&lt;br /&gt;
** &amp;lt;font color=&amp;quot;red&amp;quot;&amp;gt;Must forward port TCP/UDP 4500 and TCP/UDP 500 in &amp;#039;&amp;#039;router&amp;#039;&amp;#039; to Cisco837.&amp;lt;/font&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Cisco837(privatenet) -&amp;gt; PAT-Router -&amp;gt; Internet -&amp;gt; Cisco2811&amp;lt;br /&amp;gt;&lt;br /&gt;
=== Cisco 837 ===&lt;br /&gt;
 crypto isakmp policy 5&lt;br /&gt;
  encr 3des&lt;br /&gt;
  authentication pre-share&lt;br /&gt;
  group 2&lt;br /&gt;
  lifetime 28800&lt;br /&gt;
 crypto isakmp key &amp;#039;&amp;#039;&amp;#039;n3tInS&amp;#039;&amp;#039;&amp;#039; address 167.142.60.62 &amp;#039;&amp;#039;(peer router)&amp;#039;&amp;#039;&lt;br /&gt;
 crypto isakmp nat keepalive 10&lt;br /&gt;
 !&lt;br /&gt;
 crypto ipsec transform-set &amp;#039;&amp;#039;&amp;#039;STRONG&amp;#039;&amp;#039;&amp;#039; esp-3des esp-sha-hmac &lt;br /&gt;
 !&lt;br /&gt;
 crypto map &amp;#039;&amp;#039;&amp;#039;CISCO&amp;#039;&amp;#039;&amp;#039; 10 ipsec-isakmp &lt;br /&gt;
  set peer 167.142.60.62&lt;br /&gt;
  set transform-set &amp;#039;&amp;#039;&amp;#039;STRONG&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
  set pfs group2&lt;br /&gt;
  match address &amp;#039;&amp;#039;&amp;#039;101&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !&lt;br /&gt;
 !                          &amp;#039;&amp;#039;(local LAN subnet)&amp;#039;&amp;#039;  &amp;#039;&amp;#039;(remote LAN subnet)&amp;#039;&amp;#039;&lt;br /&gt;
 access-list 101 permit ip &amp;#039;&amp;#039;&amp;#039;198.133.143.0 0.0.0.255 167.142.49.0 0.0.0.255&amp;#039;&amp;#039;&amp;#039; log&lt;br /&gt;
 !&lt;br /&gt;
 interface Ethernet0&lt;br /&gt;
  description To_F1-3&lt;br /&gt;
  ip address dhcp&lt;br /&gt;
  &amp;#039;&amp;#039;&amp;#039;crypto map CISCO&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !&lt;br /&gt;
 interface Ethernet2&lt;br /&gt;
  description F4_to_LAN&lt;br /&gt;
  ip address 198.133.143.254 255.255.255.0&lt;br /&gt;
 !&lt;br /&gt;
=== Cisco 2811 ===&lt;br /&gt;
 crypto isakmp policy 5&lt;br /&gt;
  encr 3des&lt;br /&gt;
  authentication pre-share&lt;br /&gt;
  group 2&lt;br /&gt;
  lifetime 28800&lt;br /&gt;
 crypto isakmp key &amp;#039;&amp;#039;&amp;#039;n3tInS&amp;#039;&amp;#039;&amp;#039; hostname home.gotdns.com&lt;br /&gt;
 crypto isakmp nat keepalive 10&lt;br /&gt;
 !&lt;br /&gt;
 crypto ipsec transform-set &amp;#039;&amp;#039;&amp;#039;STRONG&amp;#039;&amp;#039;&amp;#039; esp-3des esp-sha-hmac &lt;br /&gt;
 !&lt;br /&gt;
 !&lt;br /&gt;
 !&lt;br /&gt;
 crypto map &amp;#039;&amp;#039;&amp;#039;CISCO&amp;#039;&amp;#039;&amp;#039; 10 ipsec-isakmp &lt;br /&gt;
  set peer &amp;#039;&amp;#039;&amp;#039;home.gotdns.com&amp;#039;&amp;#039;&amp;#039; dynamic&lt;br /&gt;
  set transform-set &amp;#039;&amp;#039;&amp;#039;STRONG&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
  set pfs group2&lt;br /&gt;
  match address &amp;#039;&amp;#039;&amp;#039;101&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !                          &amp;#039;&amp;#039;(local LAN subnet)&amp;#039;&amp;#039;  &amp;#039;&amp;#039;(remote LAN subnet)&amp;#039;&amp;#039;&lt;br /&gt;
 access-list 101 permit ip &amp;#039;&amp;#039;&amp;#039;167.142.49.0 0.0.0.255 198.133.143.0 0.0.0.255&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !&lt;br /&gt;
 interface Serial0/0/0:0&lt;br /&gt;
  ip address 167.142.60.62 255.255.255.252&lt;br /&gt;
  encapsulation ppp&lt;br /&gt;
  &amp;#039;&amp;#039;&amp;#039;crypto map CISCO&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !&lt;br /&gt;
 interface GigabitEthernet0/0&lt;br /&gt;
  description PublicNetwork&lt;br /&gt;
  ip address 167.142.49.254 255.255.255.0&lt;br /&gt;
== WebVPN IOS (selfsigned)==&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1:&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;&lt;br /&gt;
:The following command creates the keys that are what the certificate will be referencing, they work together.&amp;lt;br /&amp;gt;&lt;br /&gt;
:It is &amp;#039;&amp;#039;&amp;#039;very&amp;#039;&amp;#039;&amp;#039; important for these keys to be &amp;#039;&amp;#039;exportable&amp;#039;&amp;#039;. This allows the keys to be moved the the redundant router.&lt;br /&gt;
 webvpn(config)#&amp;#039;&amp;#039;&amp;#039;crypto key generate rsa general-keys label&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;exportable&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 &lt;br /&gt;
 The name for the keys will be: &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039; Choose the size of the key modulus in the range&amp;lt;br /&amp;gt; of 360 to 2048 for your General Purpose Keys. Choosing a key modulus greater than 512 may take a few minutes.&lt;br /&gt;
 &lt;br /&gt;
 How many bits in the modulus [512]: 1024&amp;lt;br /&amp;gt;&lt;br /&gt;
 % Generating 1024 bit RSA keys, keys will be exportable...[OK]&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; to export a rsa keypair(public and private)&lt;br /&gt;
 webvpn(config)#&amp;#039;&amp;#039;&amp;#039;crypto key export rsa &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;key-label&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; pem url flash:&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;filename.pem&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;3des&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;passphrase&amp;#039;&amp;#039;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2:&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;&lt;br /&gt;
:Create a &amp;#039;&amp;#039;trustpoint&amp;#039;&amp;#039; to declare the CA and also specify any characteristics for the CA.&lt;br /&gt;
 webvpn(config)#&amp;#039;&amp;#039;&amp;#039;crypto pki trustpoint&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039;&lt;br /&gt;
 webvpn(ca-trustpoint)#&amp;#039;&amp;#039;&amp;#039;enrollment selfsigned &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 webvpn(ca-trustpoint)#&amp;#039;&amp;#039;&amp;#039;subject-name C=US, ST=State, CN=&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;, O=&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;me&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;, OU=&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;me&amp;#039;&amp;#039;&lt;br /&gt;
 webvpn(ca-trustpoint)#&amp;#039;&amp;#039;&amp;#039;fqdn&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039;&lt;br /&gt;
 webvpn(ca-trustpoint)#&amp;#039;&amp;#039;&amp;#039;rsakeypair&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039;&lt;br /&gt;
 webvpn(ca-trustpoint)#&amp;#039;&amp;#039;&amp;#039;exit &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3:&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;&lt;br /&gt;
:Enroll the &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039; domaint to acquire the Certificate Request key&lt;br /&gt;
 webvpn(config)#&amp;#039;&amp;#039;&amp;#039;crypto ca enroll&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039;&lt;br /&gt;
 % Start certificate enrollment .. &lt;br /&gt;
 &lt;br /&gt;
 % The subject name in the certificate will include: C=US, ST=State, CN=webvpn.domain.com, O=me, OU=me&lt;br /&gt;
 % The subject name in the certificate will include: webvpn.domain.com&lt;br /&gt;
 % Include the router serial number in the subject name? [yes/no]: no&lt;br /&gt;
 Generate Self Signed Router Certificate? [yes/no]: yes &lt;br /&gt;
 &lt;br /&gt;
 Router Self Signed Certificate successfully created&lt;br /&gt;
&lt;br /&gt;
=== WebVPN Configuration ===&lt;br /&gt;
Virtual Template interface to enable nat from private IPs&lt;br /&gt;
 interface Virtual-Template2&lt;br /&gt;
  description SSLVPN_NAT&lt;br /&gt;
  ip unnumbered BVI1&lt;br /&gt;
  &amp;#039;&amp;#039;&amp;#039;ip nat inside&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
  ip virtual-reassembly&lt;br /&gt;
  peer default ip address pool ssl-pool&lt;br /&gt;
  ppp encrypt mppe auto required&lt;br /&gt;
  ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
 !&lt;br /&gt;
Pool for dialin(vpn) computers&lt;br /&gt;
 ip local pool ssl-pool 192.168.0.200 192.168.0.205&lt;br /&gt;
&lt;br /&gt;
WebVPN web interface&lt;br /&gt;
 webvpn gateway gateway_1&lt;br /&gt;
  hostname &amp;#039;&amp;#039;webvpn.domain.com&amp;#039;&amp;#039;&lt;br /&gt;
  ip address 123.123.123.123 port 443  &lt;br /&gt;
  http-redirect port 80&lt;br /&gt;
  ssl trustpoint &amp;#039;&amp;#039;webvpn.domain..com&amp;#039;&amp;#039;&lt;br /&gt;
  logging enable&lt;br /&gt;
  inservice&lt;br /&gt;
  !&lt;br /&gt;
 webvpn install svc flash:/webvpn/anyconnect-win-2.5.1025-k9.pkg sequence 1&lt;br /&gt;
  !&lt;br /&gt;
 webvpn context mysslvpn&lt;br /&gt;
  ssl authenticate verify all&lt;br /&gt;
  !&lt;br /&gt;
  !&lt;br /&gt;
  policy group policy_1&lt;br /&gt;
    functions svc-enabled&lt;br /&gt;
    hide-url-bar&lt;br /&gt;
    svc address-pool &amp;quot;ssl-pool&amp;quot;&lt;br /&gt;
    svc default-domain &amp;quot;&amp;#039;&amp;#039;domain.com&amp;#039;&amp;#039;&amp;quot;&lt;br /&gt;
    svc keep-client-installed&lt;br /&gt;
    svc split exclude local-lans&lt;br /&gt;
    svc dns-server primary 192.168.0.254&lt;br /&gt;
    svc dns-server secondary 8.8.8.8&lt;br /&gt;
  virtual-template 2&lt;br /&gt;
  default-group-policy policy_1&lt;br /&gt;
  aaa authentication list local_auth&lt;br /&gt;
  gateway gateway_1 domain vpn&lt;br /&gt;
  logging enable&lt;br /&gt;
  inservice&lt;br /&gt;
 !&lt;br /&gt;
&lt;br /&gt;
== iPhone to IOS VPN(IPSec) ==&lt;br /&gt;
Configuration Example&lt;br /&gt;
 version 12.3&lt;br /&gt;
 service timestamps debug datetime msec localtime show-timezone&lt;br /&gt;
 service timestamps log datetime msec localtime show-timezone&lt;br /&gt;
 service password-encryption&lt;br /&gt;
 no service dhcp&lt;br /&gt;
 !&lt;br /&gt;
 hostname C2651&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** Setup aaa&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 aaa new-model&lt;br /&gt;
 aaa authentication login local_auth local&lt;br /&gt;
 aaa session-id common&lt;br /&gt;
 !&lt;br /&gt;
 !&lt;br /&gt;
 clock timezone MST -7&lt;br /&gt;
 clock summer-time MDT recurring&lt;br /&gt;
 ip cef&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** Enter a username and password here&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 username vpnuser password 7 ********************&lt;br /&gt;
 !&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** This policy is for phase 1 for the vpn client&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 crypto isakmp policy 10&lt;br /&gt;
 encr 3des&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 2&lt;br /&gt;
 lifetime 3600&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** This part sets up the group password (Group Name: VPNCLIENT/Secret: secretkey)&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** make sure you enter your dns/wins/domain name also&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 crypto isakmp client configuration group VPNCLIENT&lt;br /&gt;
 key secretkey&lt;br /&gt;
 dns 10.2.2.5&lt;br /&gt;
 wins 10.2.2.5&lt;br /&gt;
 domain domain.local&lt;br /&gt;
 pool VPNCLIENT_ADDRESSES&lt;br /&gt;
 acl 101&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** we use acl 101 to control what goes in the network..&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** We setup a isakmp (phase 1) profile for the vpnclient&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** Tell it to use local_auth aaa to get the username/password&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 crypto isakmp profile vpn-isakmp-profile&lt;br /&gt;
 match identity group VPNCLIENT&lt;br /&gt;
 client authentication list local_auth&lt;br /&gt;
 isakmp authorization list local_auth&lt;br /&gt;
 client configuration address initiate&lt;br /&gt;
 client configuration address respond&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** THIS is the part where we specify PHASE 2.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** We set the transform to esp-aes 256bit with sha-hmac&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 crypto ipsec transform-set esp-aes-sha esp-aes 256 esp-sha-hmac&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** we then set up to use that transport-set and the isakmp profile&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 crypto dynamic-map VPNCLIENT_MAP 1&lt;br /&gt;
 set transform-set esp-aes-sha&lt;br /&gt;
 set security-association lifetime seconds 3600&lt;br /&gt;
 set isakmp-profile vpn-isakmp-profile&lt;br /&gt;
 reverse-route&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** lifetime may not show up as 3600 may already be the default&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** We then associate it to the vpn map.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 crypto map vpn 4 ipsec-isakmp dynamic VPNCLIENT_MAP&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** Internal NIC&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 interface FastEthernet0/0&lt;br /&gt;
 ip address 10.2.2.1 255.255.255.0&lt;br /&gt;
 no ip proxy-arp&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** External NIC&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 interface FastEthernet0/1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map vpn&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** We connect the vpn map to the external NIC&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** We specify a dhcp pool address&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 ip local pool VPNCLIENT_ADDRESSES 10.0.0.1 10.0.0.254&lt;br /&gt;
 !&lt;br /&gt;
 ! &amp;#039;&amp;#039;&amp;#039;*** we add acl 101 to accept connectivity from 10.0.0.0/24 to the internal network&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 access-list 101 remark CVPN ACL&lt;br /&gt;
 access-list 101 permit ip 10.2.2.0 0.0.0.255 10.0.0.0 0.0.0.255&lt;br /&gt;
&lt;br /&gt;
On the iPhone side:&amp;lt;br /&amp;gt;&lt;br /&gt;
*Description: &amp;lt;your choosing&amp;gt;&lt;br /&gt;
*Server: IP or hostname of the router&lt;br /&gt;
*Account: vpnuser&lt;br /&gt;
*Password: password&lt;br /&gt;
*Use Certificate: off&lt;br /&gt;
*Group Name: VPNCLIENT&lt;br /&gt;
*Secret: secretkey&lt;br /&gt;
&lt;br /&gt;
I hope this makes sense… to recap:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This config setups:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cisco VPN Client with AAA authentication.&amp;lt;br /&amp;gt;&lt;br /&gt;
Tested with CVPN Mac OS X v4.9.01 (0100)  and iPhone v2.2&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Phase 1: 3DES/SHA Group 2 Lifetime 3600 Seconds&amp;lt;br /&amp;gt;&lt;br /&gt;
Phase 2: AES256/SHA Lifetime 3600 Seconds Tunnel Mode&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Internal: 10.2.2.0/24      VPN IPs: 10.0.0.0/24   WAN: DHCP&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== iPhone to IOS VPN (PPTP) ==&lt;br /&gt;
Caveat is that it won&amp;#039;t work through firewall(client iPhone side)&amp;lt;br /&amp;gt;&lt;br /&gt;
the &amp;quot;username&amp;quot; account has to use PASSWORD not SECRET&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
username client password testclient&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1&lt;br /&gt;
 ip unnumbered Dialer0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 peer default ip address pool ssl-pool&lt;br /&gt;
 ppp mtu adaptive&lt;br /&gt;
 ppp encrypt mppe auto required&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
 ppp eap refuse callin&lt;br /&gt;
!&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group PPTPVPN&lt;br /&gt;
 ! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
 lcp renegotiation on-mismatch&lt;br /&gt;
 l2tp tunnel timeout no-session 15&lt;br /&gt;
!&lt;br /&gt;
aaa authentication ppp default local&lt;br /&gt;
aaa authorization network default local &lt;br /&gt;
!&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cisco IOS Certificate Server set-up and client enrolment ==&lt;br /&gt;
A quick step by step overview of how to configure the certificate server on a Cisco IOS device.&lt;br /&gt;
&lt;br /&gt;
The certificate server functionality was added in version 12.3(4). It is only available in in security images or higher. We can use this functionality to provide scalable authentication for VPN set-ups.&lt;br /&gt;
&lt;br /&gt;
These are the seven basic steps that are needed to configure a fictional root certificate server on the CA IOS device shown in the topology below. If you would like to try yourself the initial GNS3 net file is [here] which includes all the basic config. The lab was made using 3600 routers running Version 12.4(16a) of IOS.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Certificate Server&lt;br /&gt;
Step 	Description&lt;br /&gt;
1 	RSA key pair&lt;br /&gt;
2 	PKI Trustpoint&lt;br /&gt;
3 	Certificate Server&lt;br /&gt;
4 	Issuing Policy&lt;br /&gt;
5 	CRL&lt;br /&gt;
6 	SCEP&lt;br /&gt;
7 	Enable the Certificate server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
1. RSA Key Pair – First step is to generate a private/public key pair on the CA router. The private key will be used to sign “user” certificates and the public key will distributed and used to verify certificates. In the example below our keys are labelled CE-Key.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#conf t&lt;br /&gt;
Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;
CA(config)#crypto key generate rsa usage-keys label CA-Key modulus 2048 exportable&lt;br /&gt;
The name for the keys will be: CA-Key&lt;br /&gt;
&lt;br /&gt;
% The key modulus size is 2048 bits&lt;br /&gt;
% Generating 2048 bit RSA keys, keys will be exportable...[OK]&lt;br /&gt;
% Generating 2048 bit RSA keys, keys will be exportable...[OK]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
2. PKI Trustpoint – The trustpoint configures what key pair will be used within the certificate server.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA(config)#crypto pki trustpoint CA-Server&lt;br /&gt;
CA(ca-trustpoint)#rsakeypair CA-Key&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
3. Certificate Server – Now we create and configure the actual certificate server. We configure it using the same name as the trustpoint from step 2. Then we configure a local location for the database (this can be remote) and set the database storage level to complete. Finally we configure the X.500 name information using the X.500 distinguished name (DN) format.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#conf t&lt;br /&gt;
Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;
CA(config)#crypto pki server CA-Server&lt;br /&gt;
CA(cs-server)#database url flash:/CA-Server&lt;br /&gt;
CA(cs-server)#database level ?&lt;br /&gt;
  complete  Each issued certificate is saved to the database&lt;br /&gt;
  minimum   Minimum certificate info is saved to the database&lt;br /&gt;
  names     Certificate serial-number &amp;amp; subject name is saved to the database&lt;br /&gt;
&lt;br /&gt;
CA(cs-server)#database level complete&lt;br /&gt;
CA(cs-server)#issuer-name C=UK,L=m00nietown,O=m00nieCo,OU=x.509 certs,CN=m00nie.com VPN&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
4. Issuing Policy – We can either manually grant all certificate requests or automattically grant all requests. We will configure a password to provide some additional authentication when users try to enrol. First we configure sha-1 as the hash algorithm used to sign the certificates with (MD5 is the default). We configure the lifetime of the certificate servers signing certificate (5 years) when this expires all issued certificates are invalidated and users will have to re-enrol. Now we configure the lifetime of client issued certificates after which clients will have to re-enrol. Both lifetimes are counted in days.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#conf t&lt;br /&gt;
Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;
CA(config)#crypto pki server CA-Server&lt;br /&gt;
CA(cs-server)#hash sha1&lt;br /&gt;
CA(cs-server)#lifetime ca-certificate 1825&lt;br /&gt;
CA(cs-server)#lifetime certificate 730&lt;br /&gt;
CA(cs-server)#no grant auto&lt;br /&gt;
&amp;lt;/re&amp;gt;&lt;br /&gt;
5. CRL – Now we define the revocation policy used to create and maintain the Certificate Revocation List (CRL). In this example we configure the CRL to only be valid for an hour (the minimum) and publish the CRL on the router itself using the cdp-url http://MYROUTERIP/cgi-bin/pkiclient.exe?operation=GetCRL command. Note - to enter the “?” you may need to press “Ctrl+V” before entering it!!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#conf t&lt;br /&gt;
Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;
CA(config)#crypto pki server CA-Server&lt;br /&gt;
CA(cs-server)#lifetime crl 1&lt;br /&gt;
CA(cs-server)#cdp-url http://1.1.1.1/cgi-bin/pkiclient.exe?operation=GetCRL&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
6. SCEP – To ease admin burden and provide scalability we “configure” the use of Simple Certificate Enrollment Protocol (SCEP). This is done by enabling the IOS HTTP server.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#conf t&lt;br /&gt;
Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;
CA(config)#ip http server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
7. Enable Certificate server – Finally we enable the certificate server now that all the prereqisits have been configured :) First we must ensure that the time of the Certificate Server is correct! In this example we configure the CA router as a NTP master then enable the server. Well configured and synchronised time on all devices is very important in a PKI environment!!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA(config)#clock timezone GMT 0 0&lt;br /&gt;
CA(config)#ntp master&lt;br /&gt;
CA(config)#crypto pki server CA-Server&lt;br /&gt;
CA(cs-server)#no shutdown&lt;br /&gt;
%Some server settings cannot be changed after CA certificate generation.&lt;br /&gt;
% Please enter a passphrase to protect the private key&lt;br /&gt;
% or type Return to exit&lt;br /&gt;
Password:&lt;br /&gt;
% Password must be more than 7 characters. Try again&lt;br /&gt;
% or type Return to exit&lt;br /&gt;
Password:&lt;br /&gt;
&lt;br /&gt;
Re-enter password:&lt;br /&gt;
&lt;br /&gt;
%Some server settings cannot be changed after CA certificate generation.&lt;br /&gt;
% Exporting Certificate Server signing certificate and keys...&lt;br /&gt;
&lt;br /&gt;
% Certificate Server enabled.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now the Certificate server is configured and running :) We can validate this with the show crypto pki server command.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#show crypto pki server&lt;br /&gt;
Certificate Server CA-Server:&lt;br /&gt;
    Status: enabled&lt;br /&gt;
    Server&amp;#039;s configuration is locked  (enter &amp;quot;shut&amp;quot; to unlock it)&lt;br /&gt;
    Issuer name: C=UK,L=m00nietown,O=m00nieCo,OU=x.509 certs,CN=m00nie.com VPN&lt;br /&gt;
    CA cert fingerprint: 042C977E 813C0A67 87D794DF C16B10C2&lt;br /&gt;
    Granting mode is: manual&lt;br /&gt;
    Last certificate issued serial number: 0x1&lt;br /&gt;
    CA certificate expiration timer: 02:27:25 GMT Feb 28 2007&lt;br /&gt;
    CRL NextUpdate timer: 03:27:25 GMT Mar 1 2002&lt;br /&gt;
    Current storage dir: flash:/CA-Server&lt;br /&gt;
    Database Level: Complete - all issued certs written as &amp;lt;serialnum&amp;gt;.cer&lt;br /&gt;
CA#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Just to note that any further changes will require the certificate server to be shutdown.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Client Enrolment&lt;br /&gt;
Step 	Description&lt;br /&gt;
1 	RSA key pair&lt;br /&gt;
2 	PKI Trustpoint / SCEP&lt;br /&gt;
3 	CA certificate installation&lt;br /&gt;
4 	Erollment Request&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
1. RSA key pair – Much the same as on the CA router generate a public/private key pair.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
VPN_Guy#conf t&lt;br /&gt;
Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;
VPN_Guy(config)#crypto key generate rsa general-keys label VPN-Key modulus 2048 exportable&lt;br /&gt;
The name for the keys will be: VPN-Key&lt;br /&gt;
&lt;br /&gt;
% The key modulus size is 2048 bits&lt;br /&gt;
% Generating 2048 bit RSA keys, keys will be exportable...[OK]&lt;br /&gt;
&lt;br /&gt;
*Mar  1 04:34:57.814: %SSH-5-ENABLED: SSH 1.99 has been enabled&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
2. PKI Trustpoint / SCEP – Now we need to configure the trustpoint to tell the client how we would like it to enrol.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
VPN_Guy(config)#crypto pki trustpoint CA-Server&lt;br /&gt;
VPN_Guy(ca-trustpoint)#enrollment url http://1.1.1.1&lt;br /&gt;
VPN_Guy(ca-trustpoint)#revocation-check crl&lt;br /&gt;
VPN_Guy(ca-trustpoint)#fqdn VPN_Guy.m00nie.com&lt;br /&gt;
VPN_Guy(ca-trustpoint)#subject-name CN=VPN_Guy,OU=X.509,O=m00nieCo,C=UK&lt;br /&gt;
VPN_Guy(ca-trustpoint)#rsakeypair VPN-Key&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
3. CA certificate – Now we need to install the CA server certificate (and verify it).&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
VPN_Guy(config)#crypto pki authenticate CA-Server&lt;br /&gt;
Certificate has the following attributes:&lt;br /&gt;
       Fingerprint MD5: 042C977E 813C0A67 87D794DF C16B10C2&lt;br /&gt;
      Fingerprint SHA1: 8B182326 5FD01A2A 67572725 D3667D64 73FE9D30&lt;br /&gt;
&lt;br /&gt;
% Do you accept this certificate? [yes/no]: yes&lt;br /&gt;
Trustpoint CA certificate accepted.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
verify the fingerprint against the output of show crypto pki server on the Certificate server.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#show crypto pki server&lt;br /&gt;
 ..&lt;br /&gt;
    CA cert fingerprint: 042C977E 813C0A67 87D794DF C16B10C2&lt;br /&gt;
..&lt;br /&gt;
&lt;br /&gt;
4. Enrolment request – Now we simple enrol with the certificate server.&lt;br /&gt;
&lt;br /&gt;
 VPN_Guy(config)#crypto pki enroll CA-Server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Then on the CA router&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CA#crypto pki server CA-Server info requests&lt;br /&gt;
Enrollment Request Database:&lt;br /&gt;
&lt;br /&gt;
Subordinate CA certificate requests:&lt;br /&gt;
ReqID  State      Fingerprint                      SubjectName&lt;br /&gt;
--------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
RA certificate requests:&lt;br /&gt;
ReqID  State      Fingerprint                      SubjectName&lt;br /&gt;
--------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Router certificates requests:&lt;br /&gt;
ReqID  State      Fingerprint                      SubjectName&lt;br /&gt;
--------------------------------------------------------------&lt;br /&gt;
1      granted    BE142DCED9C067269D1F4E740C34B77F hostname=VPN_Guy.m00nie.com,cn=VPN_Guy,ou=X.509,o=m00nieCo,c=UK&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
And grant the request like with the command crypto pki server CA-Server grant 1.&lt;br /&gt;
&lt;br /&gt;
Now we can confirm that the VPN_Guy router has the signed certificate returned from the Certificate server&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
VPN_Guy#show crypt pk certificates&lt;br /&gt;
Certificate&lt;br /&gt;
  Status: Available&lt;br /&gt;
  Certificate Serial Number: 02&lt;br /&gt;
  Certificate Usage: General Purpose&lt;br /&gt;
  Issuer:&lt;br /&gt;
    c=UK&lt;br /&gt;
    l=m00nietown&lt;br /&gt;
    o=m00nieCo&lt;br /&gt;
    ou=x.509 certs&lt;br /&gt;
    cn=m00nie.com VPN&lt;br /&gt;
  Subject:&lt;br /&gt;
    Name: VPN_Guy.m00nie.com&lt;br /&gt;
    hostname=VPN_Guy.m00nie.com&lt;br /&gt;
    cn=VPN_Guy&lt;br /&gt;
    ou=X.509&lt;br /&gt;
    o=m00nieCo&lt;br /&gt;
    c=UK&lt;br /&gt;
  CRL Distribution Points:&lt;br /&gt;
&lt;br /&gt;
http://1.1.1.1/cgi-bin/pkiclient.exeoperation=GetCRL&lt;br /&gt;
&lt;br /&gt;
  Validity Date:&lt;br /&gt;
    start date: 00:19:30 UTC Mar 1 2002&lt;br /&gt;
    end   date: 00:19:30 UTC Feb 29 2004&lt;br /&gt;
  Associated Trustpoints: CA-Server&lt;br /&gt;
&lt;br /&gt;
CA Certificate&lt;br /&gt;
  Status: Available&lt;br /&gt;
  Certificate Serial Number: 01&lt;br /&gt;
  Certificate Usage: Signature&lt;br /&gt;
  Issuer:&lt;br /&gt;
    c=UK&lt;br /&gt;
    l=m00nietown&lt;br /&gt;
    o=m00nieCo&lt;br /&gt;
    ou=x.509 certs&lt;br /&gt;
    cn=m00nie.com VPN&lt;br /&gt;
  Subject:&lt;br /&gt;
    c=UK&lt;br /&gt;
    l=m00nietown&lt;br /&gt;
    o=m00nieCo&lt;br /&gt;
    ou=x.509 certs&lt;br /&gt;
    cn=m00nie.com VPN&lt;br /&gt;
  Validity Date:&lt;br /&gt;
    start date: 00:05:27 UTC Mar 1 2002&lt;br /&gt;
    end   date: 00:05:27 UTC Feb 28 2007&lt;br /&gt;
  Associated Trustpoints: CA-Server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now we have a signed certificate installed and ready to use!&lt;br /&gt;
&lt;br /&gt;
[[Category:Linux]]&lt;/div&gt;</summary>
		<author><name>Gqwill69</name></author>
	</entry>
</feed>