A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access. The requirement is to use IKEv2 with certificate-based authentication. The administrator has installed a valid identity certificate on the router and configured the IKEv2 profile. However, remote clients are unable to establish the VPN tunnel, and the router logs show 'IKEv2 certificate authentication failed'. What is the most likely cause?
In IKEv2, the profile must specify the trustpoint that contains the router's identity certificate and the CA certificate for verifying peer certificates. If the trustpoint is not referenced or is incorrect, the router cannot validate client certificates, leading to authentication failure. This is a common misconfiguration when setting up certificate-based IKEv2. The logs indicating certificate authentication failed point to a trustpoint or PKI issue.
Why this answer
For IKEv2 certificate-based authentication, the IKEv2 profile must reference a trustpoint that contains the router's identity certificate and the CA certificate to validate peer certificates. If the trustpoint is missing or incorrect, the router cannot authenticate the client's certificate, resulting in failure. Ensuring the correct trustpoint is referenced and that the CA chain is complete resolves the issue.
Exam trap
The trap here is assuming that installing a valid certificate is sufficient, while overlooking that the IKEv2 profile must explicitly point to the trustpoint for authentication to succeed.