<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TLS version in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233526#M45189</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have disabled tls v1 and v1.1 from my firewalls , but during a recent pen test it found an issue&lt;SPAN&gt;&amp;nbsp;"Insecure SSL/TLS Protocols - LOW - External".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have used show ssl tls enabled command and can see only tls v1.2 is enabled.&lt;/P&gt;&lt;P&gt;Can you help with some other commands to check further or what could cause this issue to pop up during pen test ?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2024 11:27:51 GMT</pubDate>
    <dc:creator>lemm</dc:creator>
    <dc:date>2024-11-22T11:27:51Z</dc:date>
    <item>
      <title>TLS version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233526#M45189</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have disabled tls v1 and v1.1 from my firewalls , but during a recent pen test it found an issue&lt;SPAN&gt;&amp;nbsp;"Insecure SSL/TLS Protocols - LOW - External".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have used show ssl tls enabled command and can see only tls v1.2 is enabled.&lt;/P&gt;&lt;P&gt;Can you help with some other commands to check further or what could cause this issue to pop up during pen test ?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 11:27:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233526#M45189</guid>
      <dc:creator>lemm</dc:creator>
      <dc:date>2024-11-22T11:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: TLS version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233533#M45190</link>
      <description>&lt;P&gt;You disabled via CLI?&amp;nbsp; Maybe also check sk154532 depending on the port / service reported by the scan.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 12:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233533#M45190</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-11-22T12:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: TLS version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233539#M45191</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;DIV&gt;To check SSL V2&lt;/DIV&gt;
&lt;DIV&gt;openssl s_client -connect secureurl.com:443 -ssl2&lt;/DIV&gt;
&lt;DIV&gt;To Check SSL V3&lt;/DIV&gt;
&lt;DIV&gt;openssl s_client -connect secureurl.com:443 –ssl3&lt;/DIV&gt;
&lt;DIV&gt;To Check TLS 1.0&lt;/DIV&gt;
&lt;DIV&gt;openssl s_client -connect secureurl.com:443 –tls1&lt;/DIV&gt;
&lt;DIV&gt;To Check TLS 1.1&lt;/DIV&gt;
&lt;DIV&gt;openssl s_client -connect secureurl.com:443 –tls1_1&lt;/DIV&gt;
&lt;DIV&gt;To Check TLS 1.2&lt;/DIV&gt;
&lt;DIV&gt;openssl s_client -connect secureurl.com:443 –tls1_2&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Check that IP which was marked as vulnerable in the report.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Akos&lt;/DIV&gt;</description>
      <pubDate>Fri, 22 Nov 2024 12:59:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233539#M45191</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-22T12:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: TLS version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233542#M45192</link>
      <description>&lt;P&gt;Can you see what you have here in global properties in smart console?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28539iC1506AC5E2860183/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 13:02:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233542#M45192</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-22T13:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: TLS version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233552#M45195</link>
      <description>&lt;P&gt;You might need to disable some ciphers even though TLS 1.2 is the only thing enabled; we had something similar happen with our pen test.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk126613" target="_blank"&gt;sk126613 - Cipher configuration tool 'cipher_util' for Security Gateways&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We "passed" using this configuration:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R8110_ciphers.png" style="width: 386px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28540i2B05A96E37D39304/image-size/large?v=v2&amp;amp;px=999" role="button" title="R8110_ciphers.png" alt="R8110_ciphers.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 14:24:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233552#M45195</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-11-22T14:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: TLS version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233555#M45196</link>
      <description>&lt;P&gt;And you can test it, one-by-one too &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;openssl s_client -cipher 'ECDHE-ECDSA-AES256-SHA' -connect secureurl:443&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 14:28:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233555#M45196</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-22T14:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: TLS version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233556#M45197</link>
      <description>&lt;P&gt;Just tried with google.com, super useful command!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 14:30:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TLS-version/m-p/233556#M45197</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-22T14:30:56Z</dc:date>
    </item>
  </channel>
</rss>

