<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable TLS 1.0/1.1 for https inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152865#M25529</link>
    <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;this&amp;nbsp;&lt;SPAN&gt;sk107744&amp;nbsp;and procedure here is the same&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338#M14237" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338#M14237&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2022 07:55:31 GMT</pubDate>
    <dc:creator>Martin_Raska</dc:creator>
    <dc:date>2022-07-13T07:55:31Z</dc:date>
    <item>
      <title>Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147042#M23419</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we are dealing with the issue of how to disable the entire TLS 1.0/1.1 for outbound HTTPS inspection. I know&amp;nbsp;&lt;SPAN&gt;sk126613, but we dont want to disable ciphers but used protocol. Only TLS 1.2 from GW should be allowed. The configuration should be done one GW not clients, that's a different part.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Some ciphers are used both in TLS 1.0/1.1/1.2 eg.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TLS_DHE_RSA_WITH_AES_128_CBC_SHA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;so disabling only ciphers is not what we are looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 07:59:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147042#M23419</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2022-04-26T07:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147056#M23421</link>
      <description>&lt;P&gt;Recommend discussing this further with TAC, as I recall this needs a change to&amp;nbsp;&lt;SPAN&gt;ssl_min_ver parameter via GuiDBedit.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 09:16:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147056#M23421</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-26T09:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147064#M23422</link>
      <description>&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338/page/2" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338/page/2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 10:31:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147064#M23422</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-26T10:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147067#M23423</link>
      <description>&lt;P&gt;thx, for some reason I miss this one in search box -&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338/page/2" target="_blank" rel="noopener"&gt;Disable-TLS-1-0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 10:46:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/147067#M23423</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2022-04-26T10:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152771#M25493</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;Did you find a answer to your question? I am having the same question right now and it would be great if you could share your findings &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I also recall that you should edit GuiDBedit as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64108"&gt;@Chriz&lt;/a&gt;&amp;nbsp;mentions, but i can't seem to find the correct SK for this particular question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also created a TAC case so if you do not have the answer i will repost it here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jelle&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 08:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152771#M25493</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2022-07-12T08:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152773#M25494</link>
      <description>&lt;P&gt;Its this -&amp;nbsp;&lt;SPAN&gt;sk107744&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 09:00:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152773#M25494</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2022-07-12T09:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152787#M25500</link>
      <description>&lt;P&gt;Hi Martin,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for you answer. I find it very strange that there is no exact SK describing how to achieve this for HTTPS inspection in general. Also there is no information about what to do, when this change is applied. For example there is no information about expected behavior... do we need to reboot the gateways for this change to be active? Is there traffic disruption? All is based on assumptions...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be more exact on your previous answer, i assume that you mean that we have to execute the "workaround" mentioned in this SK?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jelle&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 12:05:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152787#M25500</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2022-07-12T12:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152788#M25501</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13122"&gt;@Martin_Raska&lt;/a&gt;&amp;nbsp;did you look here? &lt;A href="https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338#M14237" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338#M14237&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 12:17:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152788#M25501</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-12T12:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152789#M25502</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;FYI, I asked Martin if he could share the solution he found, as you can see above he used a snippet from a Sk107744 that is EOL... Why is it, that there doesn't seem to be a (up-to-date / on the point) valid SK about this topic?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jelle&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 12:24:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152789#M25502</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2022-07-12T12:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152790#M25503</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk126613: Cipher configuration tool for Security Gateways&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 12:29:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152790#M25503</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-12T12:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152791#M25504</link>
      <description>&lt;P&gt;Hi G_W_Albrecht,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response, i am aware of the cipher tool, but disabling a TLS cipher is not the same as disabling the complete tls version...&lt;/P&gt;&lt;P&gt;Is it possible to completely disable TLS1.0/1.1 via the cipher tool? I mean, for example; we can have the cipher string TLS_RSA_WITH_AES_128_CBC_SHA which can be used for both TLS.1.0 and TLS1.2... (&lt;A title="LINK" href="https://ciphersuite.info/cs/TLS_RSA_WITH_AES_128_CBC_SHA/" target="_self"&gt;LINK)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I think the cipher tool should be extended to also disable the complete protocol or a SK should be available to completely disable these protocols.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 14:21:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152791#M25504</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2022-07-12T14:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152795#M25505</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Sk107744 is not applicable to later versions, there is a cipher_util for supported versions. Which is dully mentioned in that very SK&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 12:59:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152795#M25505</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-12T12:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152799#M25507</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;,&amp;nbsp;the cipher_util is not sufficient enough to achieve my goal if i understand this correctly.&lt;/P&gt;&lt;P&gt;someone can use a specific cipher for both TLS1.0/1.1 and TLS1.2. What I mean by this is that it doesn't matter if you turn certain ciphers on or off without disabling the specific versions. (A good example is disabling TLS version 1.0 via IPS where you disable the entire version) So I am looking for an SK that specifically describes how to disable the TLS1.0 and TLS.1.1 versions without having to use an outdated SK .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 13:22:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152799#M25507</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2022-07-12T13:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152802#M25510</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Better select which strong cipher suites should be used. TLS_RSA_WITH_AES_128_CBC_SHA is a weak cipher suite - why ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;nbsp;&lt;STRONG&gt;Non-ephemeral Key Exchange:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;I class="bi bi-exclamation-triangle-fill me-1"&gt;&lt;/I&gt;&lt;STRONG&gt;Cipher Block Chaining:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="alert alert-warning" role="alert"&gt;
&lt;P&gt;In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see &lt;A class="alert-link" href="http://www.isg.rhul.ac.uk/tls/Lucky13.html" target="_blank" rel="noopener"&gt;isg.rhul.ac.uk&lt;/A&gt;). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;I class="bi bi-exclamation-triangle-fill me-1"&gt;&lt;/I&gt;&lt;STRONG&gt;Secure Hash Algorithm 1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="alert alert-warning" role="alert"&gt;
&lt;P&gt;The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see &lt;A class="alert-link" href="https://shattered.io/" target="_blank" rel="noopener"&gt;shattered.io&lt;/A&gt;).&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Jul 2022 13:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152802#M25510</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-12T13:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152803#M25511</link>
      <description>&lt;P&gt;My current cipher selection:&lt;/P&gt;
&lt;PRE&gt;SSL Inspection&lt;BR /&gt;&lt;BR /&gt;Enabled:&lt;BR /&gt;TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384&lt;BR /&gt;TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256&lt;BR /&gt;TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256&lt;BR /&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384&lt;BR /&gt;TLS_RSA_WITH_AES_256_GCM_SHA384&lt;BR /&gt;TLS_RSA_WITH_AES_128_GCM_SHA256&lt;BR /&gt;TLS_RSA_WITH_AES_256_CBC_SHA256&lt;BR /&gt;TLS_RSA_WITH_AES_128_CBC_SHA256&lt;BR /&gt;&lt;BR /&gt;Disabled:&lt;BR /&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA&lt;BR /&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256&lt;BR /&gt;TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256&lt;BR /&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256&lt;BR /&gt;TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA&lt;BR /&gt;TLS_RSA_WITH_3DES_EDE_CBC_SHA&lt;BR /&gt;TLS_RSA_WITH_AES_128_CBC_SHA&lt;BR /&gt;TLS_RSA_WITH_AES_256_CBC_SHA&lt;BR /&gt;TLS_RSA_WITH_RC4_128_MD5&lt;BR /&gt;TLS_RSA_WITH_RC4_128_SHA&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Jul 2022 14:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152803#M25511</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-12T14:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152808#M25515</link>
      <description>&lt;P&gt;I believe, we have discussed this multiple times in the community over the years. On top of what was mentioned here already,&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Disable-TLS1-0-Chekcpoint-R80-40/m-p/93023#M7186" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Disable-TLS1-0-Chekcpoint-R80-40/m-p/93023#M7186&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I do not think we have an SK for this specific topic though, other than the one mentioned above. Mind, the community team is not running SecureKnowledge. If you need an official document/guidance from Check Point, please open a TAC case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 14:21:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152808#M25515</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-12T14:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152810#M25516</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;, i understand that the community is not running SK's but my question was if there is any describing my specific question. TAC case was already created but i also wanted to ask the community, because it felt like i was not able to find the correct SK/discussion for this specific question.... Hence this question. FYI the link you provide is regarding the Gaia portal not HTTPS inspection is this correct?&amp;nbsp;Anyway... I will wait for a reply from TAC on this one.. Thanks anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 14:32:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152810#M25516</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2022-07-12T14:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152813#M25518</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;, Thanks for you answer. This gives a way to indeed get what I'm looking for. But not yet on the initial question. How do I explicitly disable TLS version 1.0/1.1 on versions higher than R77.30?&lt;/P&gt;&lt;P&gt;From sk107744 is this still the correct way?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Connect with SmartDashboard to Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRIKE&gt;Go to &lt;EM&gt;&lt;STRONG&gt;File&lt;/STRONG&gt;&lt;/EM&gt; menu - click on &lt;EM&gt;&lt;STRONG&gt;Database Revision Control...&lt;/STRONG&gt;&lt;/EM&gt; - create a revision snapshot.&lt;/STRIKE&gt;&lt;/P&gt;&lt;STRIKE&gt;Note: Database Revision Control is not supported for VSX objects (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65420" target="_blank" rel="noopener"&gt;sk65420&lt;/A&gt;).&lt;/STRIKE&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Close all SmartConsole windows (SmartDashboard, SmartView Tracker, SmartView Monitor, etc.).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Connect with &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk13009" target="_blank" rel="noopener"&gt;GuiDBedit Tool&lt;/A&gt; to Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the upper left pane, go to &lt;EM&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/EM&gt; - &lt;EM&gt;&lt;STRONG&gt;Other&lt;/STRONG&gt;&lt;/EM&gt; - &lt;EM&gt;&lt;STRONG&gt;ssl_inspection&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the upper right pane, select &lt;EM&gt;&lt;STRONG&gt;general_confs_obj&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Press CTRL+F (or go to &lt;EM&gt;&lt;STRONG&gt;Search&lt;/STRONG&gt;&lt;/EM&gt; menu - &lt;EM&gt;&lt;STRONG&gt;Find&lt;/STRONG&gt;&lt;/EM&gt;) - paste &lt;EM&gt;&lt;STRONG&gt;ssl_min_ver&lt;/STRONG&gt;&lt;/EM&gt; - click on &lt;EM&gt;&lt;STRONG&gt;Find Next&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the lower pane, right-click on the &lt;EM&gt;&lt;STRONG&gt;ssl_min_ver&lt;/STRONG&gt;&lt;/EM&gt; - select &lt;EM&gt;&lt;STRONG&gt;Edit...&lt;/STRONG&gt;&lt;/EM&gt; - select "&lt;EM&gt;&lt;STRONG&gt;TLS1.1&lt;/STRONG&gt;&lt;/EM&gt;" - click on &lt;EM&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/EM&gt;:&lt;/P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jelle_Hazenberg_0-1657636892629.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17160i827D652BA464FCC0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jelle_Hazenberg_0-1657636892629.png" alt="Jelle_Hazenberg_0-1657636892629.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Save the changes: go to &lt;EM&gt;&lt;STRONG&gt;File&lt;/STRONG&gt;&lt;/EM&gt; menu - click on &lt;EM&gt;&lt;STRONG&gt;Save All&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Close the GuiDBedit Tool.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Connect with SmartDashboard to Security Management Server / Domain Management Server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Install the policy onto the relevant Security Gateway / Cluster object.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or do we need to use the cipher_util to implicitly disable old TLS versions to get the job done? Maybe it's my way of explaining things here but i don't seem to get 1 clear answer for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyhow, there is a existing TAC case on this 1 so ill wait what they come back with &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 14:47:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152813#M25518</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2022-07-12T14:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152865#M25529</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;this&amp;nbsp;&lt;SPAN&gt;sk107744&amp;nbsp;and procedure here is the same&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338#M14237" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Disable-TLS-1-0/m-p/70338#M14237&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 07:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152865#M25529</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2022-07-13T07:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Disable TLS 1.0/1.1 for https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152889#M25533</link>
      <description>&lt;P&gt;I think there should be the SK and guide how to do it. I mean the official way, easy way as other vendors have it quite easy, one command or click in profile and its done.&lt;/P&gt;&lt;P&gt;For CP we need several threads in forum and a couple outdated SKs.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 12:24:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-TLS-1-0-1-1-for-https-inspection/m-p/152889#M25533</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2022-07-13T12:24:36Z</dc:date>
    </item>
  </channel>
</rss>

