<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI Scans Failing and Disablement of DES and DH Group 1 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276031#M46074</link>
    <description>&lt;P&gt;You may also wish to review&amp;nbsp;&lt;SPAN&gt;sk113114 more broadly&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2026 01:16:54 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2026-04-24T01:16:54Z</dc:date>
    <item>
      <title>PCI Scans Failing and Disablement of DES and DH Group 1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276015#M46065</link>
      <description>&lt;P&gt;I have a site where PCI Scans are failing for&amp;nbsp;DES and DH Group 1 vulnerabilities.&lt;/P&gt;&lt;P&gt;I'm pretty sure that we can disable DES exposure in Cluster&amp;gt;IPSEC VPN&amp;gt;Traditional Mode&amp;gt;General Properties (see pic) while following sk82900&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk82900" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk82900.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But in same pane/pic for Advanced Properties, it lists all the supported DH Groups and DH-1 Group is not selected.&lt;/P&gt;&lt;P&gt;So I need a document or sk for how/why DH Group-1 is being detected and how to disable it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cm-cluster-ipsec-props-1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34089iE72A1017C89BCE26/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cm-cluster-ipsec-props-1.png" alt="cm-cluster-ipsec-props-1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 19:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276015#M46065</guid>
      <dc:creator>D_Riddleberger</dc:creator>
      <dc:date>2026-04-23T19:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scans Failing and Disablement of DES and DH Group 1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276018#M46066</link>
      <description>&lt;P&gt;Maybe worth to check also here&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 693px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34090iC371CD4DED31ED55/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 20:10:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276018#M46066</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-04-23T20:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scans Failing and Disablement of DES and DH Group 1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276020#M46068</link>
      <description>&lt;P&gt;Are the results maybe from a GAIA embedded unit? then check out&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk184658" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk184658&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 20:23:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276020#M46068</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-04-23T20:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scans Failing and Disablement of DES and DH Group 1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276025#M46070</link>
      <description>&lt;P&gt;Hi Lesley,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, these are not embedded Gaia SMB Appliances.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 21:02:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276025#M46070</guid>
      <dc:creator>D_Riddleberger</dc:creator>
      <dc:date>2026-04-23T21:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scans Failing and Disablement of DES and DH Group 1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276031#M46074</link>
      <description>&lt;P&gt;You may also wish to review&amp;nbsp;&lt;SPAN&gt;sk113114 more broadly&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 01:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276031#M46074</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-24T01:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scans Failing and Disablement of DES and DH Group 1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276062#M46083</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Yes, that sk does provide some additional insight. Thank You.&lt;/P&gt;&lt;P&gt;I have confirmed that DES as well DH Group-1 is not used in any VPN Communities. As I did not think that it was. The problem is that the gateways are 'responding to' some level of acknowledgement/response from the scan that features/functionality for DES and DH Group 1 are enabled. I also confirmed from the scan report that it is IPSEC that is being flagged. So, I think we are in the clear for DES and DH Group 1 when it comes to SSH and Remote Access&amp;nbsp;features/functionality whereas those can be turned off in Global Properties&amp;gt;Remote Access&amp;gt;VPN Auth and Encryption &amp;lt;edit algorithms&amp;gt;. I'm still digging....&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 17:47:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276062#M46083</guid>
      <dc:creator>D_Riddleberger</dc:creator>
      <dc:date>2026-04-24T17:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Scans Failing and Disablement of DES and DH Group 1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276063#M46084</link>
      <description>&lt;P&gt;Hey Dan,&lt;/P&gt;
&lt;P&gt;Seems like you have it all configured properly. Might be worth TAC case to confirm, for sure. I did check in smart console and all the settings you mentioned are 100% right.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 18:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Scans-Failing-and-Disablement-of-DES-and-DH-Group-1/m-p/276063#M46084</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-04-24T18:54:35Z</dc:date>
    </item>
  </channel>
</rss>

