logging <hostname-or-IP-address> tls certificate match-x509-cert-san-ipv4-or-ipv6 <IP-address-to-match>

Prev Next

For remote logging, add an explicit TLS X.509 certificate matching rule to match the remote syslog server by IP address in the subjectAltName (SAN) field.

For strict compliance with the Common Criteria (CC-NDcPP) certification, syslog server certification verification for remote logging fails if the certificate is configured with an IP address in the Common Name (CN) field. To configure a remote syslog server by its IP address, the IP address must be in the Subject Alternative Name (subjectAltName) field.

To add multiple matching IP addresses, configure a rule for each IP address separately.

Alternatively, you can add a rule to match the remote server by hostname using the logging <hostname-or-IP-address> tls certificate match-x509-cert-san-or-cn-hostname <hostname> command or by email address using the logging <hostname-or-IP-address> tls certificate match-x509-cert-san-email <email-addr> command.

Syntax

[no] logging <hostname-or-IP-address> tls certificate match-x509-cert-san-ipv4-or-ipv6 <IP-address-to-match>

Parameters

<term>
no
</term>
Disable matching of the subjectAltName field of a certificate to the specified IP address. This is the default.<term>
hostname-or-IP-address
</term>
The hostname or IP address of the remote logging server.<term>
IP-address-to-match
</term>
The IPv4 or IPv6 address to be matched in the certificate's subjectAltName field. This can be different from the log server address specified by the <hostname-or-IP-address> parameter (for example, if the server is reached through a firewall).

Example

The following example enables an explicit X.509 rule to match the subjectAltName field of a certificate by the specified IP address.

hostname (config) # logging 192.0.2.1 tls certificate match-x509-cert-san-ipv4-or-ipv6 192.0.2.24

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 9.0.2