V7防火墙配置单独的证书认证时,认证成功但提示授权失败:
请问如何对证书认证进行授权?
ssl server-policy 1
pki-domain 1
ciphersuite rsa_aes_128_cbc_sha rsa_des_cbc_sha rsa_rc4_128_md5 rsa_rc4_128_sha rsa_3des_ede_cbc_sha rsa_aes_256_cbc_sha exp_rsa_rc4_md5 exp_rsa_rc2_md5 exp_rsa_des_cbc_sha dhe_rsa_aes_128_cbc_sha dhe_rsa_aes_256_cbc_sha
client-verify enable
#
ssl client-policy 1
pki-domain 1
prefer-cipher dhe_rsa_aes_256_cbc_sha rsa_aes_256_cbc_sha dhe_rsa_aes_128_cbc_sha rsa_aes_128_cbc_sha rsa_3des_ede_cbc_sha exp_rsa_des_cbc_sha rsa_des_cbc_sha rsa_rc4_128_md5 rsa_rc4_128_sha exp_rsa_rc4_md5 exp_rsa_rc2_md5
#
sslvpn gateway ssl
ip address 192.168.56.1 port 4433
ssl server-policy 1
service enable
#
sslvpn context ssl
ssl client-policy 1
gateway ssl domain 111
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool sslpool mask 255.255.255.0
ip-tunnel dns-server primary 223.5.5.5
ip-route-list in
include 1.1.1.1 255.255.255.255
policy-group sslvpn
filter ip-tunnel acl 3000
ip-tunnel access-route ip-route-list in
default-policy-group sslvpn
certificate-authentication enable
authentication use any-one
service enable
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论