<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable CBC mode cipher and enable GCM cipher mode for https inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/95277#M12455</link>
    <description>&lt;P&gt;We have already on R80.30 and we are facing the same issue that the all CBC Cipher are showing enable for all the application.&lt;/P&gt;&lt;P&gt;Is there any way to restrict ciphers for specific natted IP?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2020 14:09:06 GMT</pubDate>
    <dc:creator>Suresh_Kumar</dc:creator>
    <dc:date>2020-08-26T14:09:06Z</dc:date>
    <item>
      <title>Disable CBC mode cipher and enable GCM cipher mode for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/63090#M12453</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have R80.10 with https inspection on, does anyone know how to disable the CBC mode cipher for&amp;nbsp;TLS_ECDHE_RSA * in the https inspection?&lt;/P&gt;&lt;P&gt;There an SK show how to allow specific cipher suites only for VPN in R80.10&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613&amp;amp;partition=Advanced&amp;amp;product=Security#10" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613&amp;amp;partition=Advanced&amp;amp;product=Security#10&lt;/A&gt;&lt;/P&gt;&lt;P&gt;any help would be great, thank you.&lt;/P&gt;&lt;P&gt;TG&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 19:06:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/63090#M12453</guid>
      <dc:creator>TG_Mai</dc:creator>
      <dc:date>2019-09-18T19:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Disable CBC mode cipher and enable GCM cipher mode for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/65843#M12454</link>
      <description>See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613&lt;/A&gt;&lt;BR /&gt;Note that if you're using HTTPS Inspection, it's a good idea to upgrade to R80.30 as it supports additional ciphers, has a better utility to configure what it supported/allowed, and improved SNI support.</description>
      <pubDate>Thu, 24 Oct 2019 18:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/65843#M12454</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-24T18:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Disable CBC mode cipher and enable GCM cipher mode for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/95277#M12455</link>
      <description>&lt;P&gt;We have already on R80.30 and we are facing the same issue that the all CBC Cipher are showing enable for all the application.&lt;/P&gt;&lt;P&gt;Is there any way to restrict ciphers for specific natted IP?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 14:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/95277#M12455</guid>
      <dc:creator>Suresh_Kumar</dc:creator>
      <dc:date>2020-08-26T14:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disable CBC mode cipher and enable GCM cipher mode for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/131087#M19296</link>
      <description>&lt;P&gt;Hi Suresh,&lt;/P&gt;&lt;P&gt;Hope you are doing well. Want to ask, you manage to have your questions answered? if you do could you share with me the steps.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 07:37:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/131087#M19296</guid>
      <dc:creator>Zatimus</dc:creator>
      <dc:date>2021-10-06T07:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Disable CBC mode cipher and enable GCM cipher mode for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/131091#M19298</link>
      <description>&lt;P&gt;A good starting point is&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104562&amp;amp;partition=Advanced&amp;amp;product=HTTPS" target="_blank"&gt;sk104562: Supported &lt;STRONG&gt;cipher&lt;/STRONG&gt; suites for &lt;STRONG&gt;HTTPS&lt;/STRONG&gt; &lt;STRONG&gt;Inspection&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;that lists supported ciphers for many versions. Then use&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk126613: &lt;STRONG&gt;Cipher&lt;/STRONG&gt; configuration &lt;STRONG&gt;tool&lt;/STRONG&gt; for Security Gateways&lt;/A&gt;&amp;nbsp;to configure it as requested.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 08:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/131091#M19298</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-06T08:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Disable CBC mode cipher and enable GCM cipher mode for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/191028#M35274</link>
      <description>&lt;P&gt;is there any way to block the CBC ciphers on a NAT ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 06:11:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/191028#M35274</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-08-30T06:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Disable CBC mode cipher and enable GCM cipher mode for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/191045#M35276</link>
      <description>&lt;P&gt;Please explain - what is a NAT IP for you? Usually, allowed ciphers can be set for SSH, SSL VPN and Multiportal.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 07:27:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-CBC-mode-cipher-and-enable-GCM-cipher-mode-for-https/m-p/191045#M35276</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-30T07:27:27Z</dc:date>
    </item>
  </channel>
</rss>

