<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Weak Ciphers Removal in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Weak-Ciphers-Removal/m-p/51247#M12342</link>
    <description>&lt;P&gt;I would use sk126613 for R80.xx version.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2019 11:14:14 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-04-18T11:14:14Z</dc:date>
    <item>
      <title>Weak Ciphers Removal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Weak-Ciphers-Removal/m-p/51240#M12341</link>
      <description>&lt;P&gt;On our MAB SSL VPN, I have restricted this to only use TLS1.2 and now I want to remove the weak cipher suites as shown.&lt;/P&gt;&lt;P&gt;I can see 2 possible ways of removing these:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120774&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613#20" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126613#20&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Is there a better one of the 2 methods to use?&lt;/P&gt;&lt;P&gt;I was thinking the 2nd link would be better as it gives a full list of the individual ciphers that you can either allow or block.&lt;/P&gt;&lt;P&gt;Any suggestions welcome.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 10:02:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Weak-Ciphers-Removal/m-p/51240#M12341</guid>
      <dc:creator>NeilDavey</dc:creator>
      <dc:date>2019-04-18T10:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Weak Ciphers Removal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Weak-Ciphers-Removal/m-p/51247#M12342</link>
      <description>&lt;P&gt;I would use sk126613 for R80.xx version.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 11:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Weak-Ciphers-Removal/m-p/51247#M12342</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-04-18T11:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Weak Ciphers Removal</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Weak-Ciphers-Removal/m-p/51252#M12343</link>
      <description>&lt;P&gt;This is what we did:&lt;/P&gt;&lt;P&gt;Global Properties &amp;gt; Smartboard Customization &amp;gt; Configure &amp;gt; Portal Properties: changed snx_ssl_min_ver to TLS1.1 and max to TLS1.2&lt;/P&gt;&lt;P&gt;followed: sk120774 (your first link but this was when the gateways where R77.30)&lt;/P&gt;&lt;P&gt;and also on the gateways:&lt;/P&gt;&lt;P&gt;ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 CPTLS_ACCEPT_ECDHE 1&lt;/P&gt;&lt;P&gt;ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 CPTLS_PROPOSE_ECDHE 1&lt;/P&gt;&lt;P&gt;ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 DISABLE_3DES 1&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 11:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Weak-Ciphers-Removal/m-p/51252#M12343</guid>
      <dc:creator>Mikel_Aanstoot</dc:creator>
      <dc:date>2019-04-18T11:40:23Z</dc:date>
    </item>
  </channel>
</rss>

