Cisco 3002 - VPN Hardware Client Dokumentacja Strona 148

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 147
11-10
VPN 3002 Hardware Client Reference, Release 4.0
OL-3813-01
Chapter 11 Policy Management
Configuration | Policy Management | Certificate Validation
Operator
The Operators are =, !=, * or !*. This section defines each of the operators, and explains how they are
used in a sample Matching Criteria set at
CN=IDCert,OU*Cisco,ISSUER-CN!=Entrust,ISSUER-OU!*wonderland
Value
The value to be matched against. The VPN 3002 automatically places text values within double quotes.
To enter values manually, follow the rules on the screen. Values are not case-sensitive.
Append
To enter the next part of a rule, click Append. When you click Append, the VPN Concentrator adds on
the part you have defined to the rule that appears under Matching Criteria. In this way, you can build a
complex rule testing on multiple components. The VPN Concentrator checks the information in the
certificate against all parts of the rule. All parts must test true for the rule to match for this group.
Matching Criteria
The matching criteria text box displays the rule. You can create or edit the rule directly in this box. If
you create a rule in this way, separate the components with commas. Also, be sure to add double quotes
around the value. If the value itself contains double quotes, replace them with two double quotes. For
example, enter the value “Tech” Eng as:
“““Tech”” Eng”.
Apply/Cancel
After entering all parts of the rule for this group, click Apply to complete or Cancel to cancel it.
Reminder:
To save the active configuration and make it the boot configuration, click the Save Needed icon at the
top of the Manager window.
To discard your settings, click Cancel. The Manager returns to the Configuration | Policy Management
| Certificate Group Matching | Rules screen, and the Rules list is unchanged.
Field Content Example
Equals (=) The distinguished name field must
exactly match the value.
CN=”ID Cert” specifies an exact match on
the CN.
Contains (*) The distinguished name field must
contain the value within it.
OU*”Cisco” specifies any OU that contains
the string Cisco.
Not Equals (!=) The distinguished name field must
not match the value.
ISSUER-CN! “Entrust” specifies that the
Issuer CN must not equal Entrust.
Does Not Contain (!*) The distinguished name field must
not contain the value within it.
ISSUER-OU!* specifies that the Issuer OU
must not contain wonderland.
Przeglądanie stron 147
1 2 ... 143 144 145 146 147 148 149 150 151 152 153 ... 317 318

Komentarze do niniejszej Instrukcji

Brak uwag