A network administrator is configuring a Cisco IOS router to support IPsec VPN for remote workers. The security policy requires that the router authenticate users via digital certificates issued by a corporate PKI. The administrator has already configured the CA trustpoint and obtained a certificate. Which command must be used in the ISAKMP policy to specify that RSA signatures (digital certificates) should be used for authentication?
The 'authentication rsa-sig' command within the ISAKMP policy specifies that RSA signatures should be used for authentication. This means the router will use digital certificates obtained from a CA to authenticate peers. This matches the requirement to use digital certificates issued by a corporate PKI. The command is configured under 'crypto isakmp policy' configuration mode.
Why this answer
In an ISAKMP policy for IKEv1, the 'authentication rsa-sig' command enables RSA signature authentication, which relies on digital certificates. The other options are incorrect: pre-share uses pre-shared keys, rsa-encr uses encrypted nonces, and eap is used for EAP authentication, typically in IKEv2. The policy requires certificate-based authentication, so rsa-sig is the correct command.
Exam trap
The trap here is confusing rsa-sig with rsa-encr; rsa-sig uses digital certificates for authentication, while rsa-encr uses RSA encrypted nonces without certificates.