Configure certificate maps

Use certificate maps to define rules that match user certificates to connection profiles. These maps enable certificate authentication, prompting remote users for a client certificate regardless of the configured authentication method. If no certificate maps match, Cloud-Delivered Firewall Management Center selects the default connection profile. You must define certificate map rules in certificate map objects. For more information about certificate map objects, refer to Certificate map objects.

Procedure


Step 1

Choose Secure Connections > Remote Access VPN.

Step 2

Click the edit icon next to the remote access VPN policy.

Step 3

Click the Advanced tab.

Step 4

In the left pane, click Certificate Maps.

Step 5

In General Settings for Connection Profile Mapping pane, configure these parameters:

Select one or both options to establish certificate authentication and map the client to a connection profile.

  • Check the Use Group URL if Group URL and Certificate Map match different Connection profiles check box if required.

  • Check the Use the configured rules to match a certificate to a Connection Profile check box to apply the rules defined in the connection profile maps.

Step 6

In Certificate to Connection Profile Mapping, click Add Mapping to create a certificate to connection profile mapping for this remote access VPN policy.

In the Add Connection Profile to Certificate Map dialog box, configure these parameters:

  1. From the Certificate Map Name drop-down list, choose a certificate map for the connection profile.

  2. From the Connection Profile drop-down list, choose a connection profile to use when the client certificate satisfies the rules of the map.

  3. Click OK to create the mapping.

Step 7

Click Save.