Set up LANCOM Advanced VPN Client for certificate connections

To use the LANCOM Advanced VPN Client to dial-in to a LANCOM router, the appropriate profile settings must be adjusted to allow for the use of certificates.

  1. In the IPSec General Settings for the profile, set the IKE policy to 'RSA signature'.




  1. Switch the identity to 'ASN1 Distinguished Names'. The 'identity' can remain blank since this information is taken from the certificate.




  1. For the IP address assignment use the 'IKE Config Mode'.




  1. For the Certificate Check you can optionally place a limitation on the certificates accepted by the LANCOM Advanced VPN Client. To do this, you define the user and/or the issuer of the incoming certificate and, if applicable, the associated "fingerprint".




  1. After storing the adapted connection profile, click on the menu item Configuration / Certificates to open the settings for the User Certificate.