> For the complete documentation index, see [llms.txt](https://ccie-sp.gitbook.io/ccie-spv5.1-labs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ccie-sp.gitbook.io/ccie-spv5.1-labs/labs/mdt/dial-in-with-two-way-tls.md).

# Dial-In with two-way TLS

Continuing from the previous labs, the router should still have the collector’s cert in /misc/config/grpc/dialout/dialout.pem. Copy this to /misc/config/grpc/ca.cert.

Configure two-way TLS for the dial-in session so that the collector also must present its cert to the router for verification.

On the Ubuntu node, enable the following lines in **telegraf\_dial\_in.conf**:

<div align="left"><figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2Fp5c3z09o4YsjZOFQpUHy%2Fimage.png?alt=media&amp;token=1ad1c02d-1c4b-47cd-94e7-f4d9fc2b90ae" alt=""><figcaption></figcaption></figure></div>

Ensure these certs are still loaded via the **docker-compose.yaml** file:

<div align="left"><figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2FW7oxdL56WUYDnavLxdA8%2Fimage.png?alt=media&amp;token=e3cb9fcf-5ae3-444c-9a60-290815ca8d0d" alt=""><figcaption></figcaption></figure></div>

Stop and start the docker container:

```
sudo docker compose down
sudo docker compose up -d
```

## Answer <a href="#id-0b7a150c-e5f5-48ab-a4a0-2ab330668024" id="id-0b7a150c-e5f5-48ab-a4a0-2ab330668024"></a>

```
#XR1
run cp /misc/config/grpc/dialout/dialout.pem /misc/config/grpc/ca.cert

grpc
 tls-mutual
```

The **grpc tls-mutual** command requires that TLS verification is preformed in both directions. By default, only the router presents its own cert to the collector for verification during a dial-in session. But with **tls-mutual**, the collector also presents its own cert to the router for mutual TLS authentication.

The same CA cert can be used that was used for dialout. However, with dial-in mutual TLS, the router does not look at the dialout.pem file. It uses the ca.cert file to authenticate the collector. For this reason, we must copy the dialout.pem file to the ca.cert file.

```
run cp /misc/config/grpc/dialout/dialout.pem /misc/config/grpc/ca.cert
```

At this point, we likely need to restart the EMSD process.

```
process restart emsd
```

We should see that the MDT dial-in session is now **TLS-mutual** instead of just **TLS**.

<div align="left"><figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2Fo58pFkTsS9FVZqLynyUQ%2Fimage.png?alt=media&amp;token=d598bb7a-d587-4d45-817d-c4f3dfe78f68" alt=""><figcaption></figcaption></figure></div>

## Further Reading <a href="#id-19c6aea9-148a-4563-911f-d389aaccd417" id="id-19c6aea9-148a-4563-911f-d389aaccd417"></a>

These labs were mostly created using the following tutorial on XRdocs: <https://xrdocs.io/telemetry/tutorials/telemetry-stack-update-grpc-tls/>
