Configure certificate maps
Use certificate maps to define rules that match user certificates to connection profiles. These maps enable certificate authentication, prompting remote users for a client certificate regardless of the configured authentication method. If no certificate maps match, Cloud-Delivered Firewall Management Center selects the default connection profile. You must define certificate map rules in certificate map objects. For more information about certificate map objects, refer to Certificate map objects.
Procedure
Step 1 | Choose . |
Step 2 | Click the edit icon next to the remote access VPN policy. |
Step 3 | Click the Advanced tab. |
Step 4 | In the left pane, click Certificate Maps. |
Step 5 | In General Settings for Connection Profile Mapping pane, configure these parameters: Select one or both options to establish certificate authentication and map the client to a connection profile.
|
Step 6 | In Certificate to Connection Profile Mapping, click Add Mapping to create a certificate to connection profile mapping for this remote access VPN policy. In the Add Connection Profile to Certificate Map dialog box, configure these parameters:
|
Step 7 | Click Save. |