Use the CLI commands to import the public certificate and private key for the SSL server and the root certificate authority (CA) certificate to establish a secure SSL connection for the Communications Broker Sender (Comm Broker) input module on the Network Security appliance.
Important
Mutual authentication between the Network Security appliance and the third-party log forwarding server is required. The third-party server must provide a client certificate and the client certificate must be trusted by the Network Security appliance. See your third-party log forwarding server documentation for steps to set up a client TLS certificate.
Important
After you apply the certificates to establish a secure SSL connection, use the
commbroker enablecommand to enable the Comm Broker.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Import the public certificate from the
bootstrap.crtfile that you already downloaded.hostname (config) # crypto certificate name <certificateName>public-cert pem"<pemString>" [comment"<comment>"]
where:
<certificateName>is a name of your choice that uniquely identifies the certificate for the SSL server.<pemString>is the public certificate PEM string for the SSL server. Copy the certificate content from the bootstrap.crt file. Paste the certificate content of the PEM string within the quotes.<comment>is the text for the comment.
Import the private key PEM string from the
bootstrap.pemfile that you already downloaded.hostname (config) # crypto certificate name <certificateName> private-key pem"<pemString>"
where
<pemString>is the private key PEM string for the SSL server. Copy the private key content from thebootstrap.pemfile. Paste the private key content of the PEM string within the quotes.Apply the uploaded certificate for the SSL server to the Comm Broker.
hostname (config) # commbroker ssl server certificate name <certificateName>
where
<certificateName>is the name that you already configured to uniquely identify the certificate for the Comm Broker input module.Verify that the public certificate for the SSL server has been imported.
hostname (config) # show commbroker ssl certificate Commbroker ssl server certificate: cb-ssl-certs Commbroker ssl rootca certificate: rootCA
Save your changes.
hostname (config) # write memory
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Import the root private key PEM string from the
rootCA.pemfile that you already downloaded for your CA.hostname (config) # crypto certificate name <certificateName> private-key pem"<pemString>"where
<pemString>is the root private key PEM string for the root CA certificate. Copy the private key content from therootCA.pemfile. Paste the private key content of the PEM string within the quotes.Apply the uploaded root CA certificate to the Comm Broker input module.
hostname (config) # commbroker ssl rootca certificate name <certificateName>
where
<certificateName>is the name that you already configured to uniquely identify the root CA certificate for the Comm Broker input module.Verify that the root CA certificate has been imported.
hostname (config) # show commbroker ssl certificate Commbroker ssl server certificate: cb-ssl-certs Commbroker ssl rootca certificate: rootCA
Save your changes.
hostname (config) # write memory