<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable weak ciphers on remote access clients? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203175#M4181</link>
    <description>&lt;P&gt;These are the settings for the IKE algorithms. So they should not impact how the IPsec traffic is tunneled over HTTPS in Visitor Mode. It seems like the Visitor Mode is part of the&amp;nbsp;MultiPortal daemon (&lt;A title="Visitor Mode port grayed out when Mobile Access Blade is enabled" href="https://support.checkpoint.com/results/sk/sk107852" target="_self"&gt;sk107852&lt;/A&gt;) and is therefore affected by the settings of the &lt;EM&gt;cipher_util&lt;/EM&gt;.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jan 2024 07:38:36 GMT</pubDate>
    <dc:creator>Martin_Schwarz</dc:creator>
    <dc:date>2024-01-16T07:38:36Z</dc:date>
    <item>
      <title>Disable weak ciphers on remote access clients?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203117#M4179</link>
      <description>&lt;P&gt;We hardened a customers' security gatway via &lt;EM&gt;cipher_util&lt;/EM&gt; (&lt;A href="https://support.checkpoint.com/results/sk/sk126613" target="_self"&gt;sk126613&lt;/A&gt;) and disabled all weak ciphers to reach PCI DSS compliance. Then remote access clients (&lt;EM&gt;MacOS using visitor mode&lt;/EM&gt;) failed to connect, so&amp;nbsp;we opened a SR.&lt;BR /&gt;&lt;BR /&gt;Check Point support advised to enable these three ciphers according to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108426" target="_self"&gt;sk108426&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;TLS_RSA_WITH_RC4_128_MD5&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;TLS_RSA_WITH_AES_128_CBC_SHA&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;TLS_RSA_WITH_AES_256_CBC_SHA&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;and noted:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;It is best to keep the 3 ciphers on to avoid any issues regarding remote access/mobile access connectivity&lt;BR /&gt;Currently there is no ETA to whether the client will be on the same cipher suite as the GW itself.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Of course that doesn't satisfy our customer as it conflicts with PCI DSS requirements for strong ciphers, such as SHA-2.&lt;BR /&gt;&lt;STRONG&gt;Is there any other solution or workaround available?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 21:28:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203117#M4179</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2024-01-15T21:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Disable weak ciphers on remote access clients?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203148#M4180</link>
      <description>&lt;P&gt;Hey Danny,&lt;/P&gt;
&lt;P&gt;Guy in TAC told me while back that some of these settings in global properties may have something to do with it, but I never ended up testing it, so hard to say.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24070i11F3A2CF0B09E9DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 19:49:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203148#M4180</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-15T19:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Disable weak ciphers on remote access clients?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203175#M4181</link>
      <description>&lt;P&gt;These are the settings for the IKE algorithms. So they should not impact how the IPsec traffic is tunneled over HTTPS in Visitor Mode. It seems like the Visitor Mode is part of the&amp;nbsp;MultiPortal daemon (&lt;A title="Visitor Mode port grayed out when Mobile Access Blade is enabled" href="https://support.checkpoint.com/results/sk/sk107852" target="_self"&gt;sk107852&lt;/A&gt;) and is therefore affected by the settings of the &lt;EM&gt;cipher_util&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 07:38:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203175#M4181</guid>
      <dc:creator>Martin_Schwarz</dc:creator>
      <dc:date>2024-01-16T07:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Disable weak ciphers on remote access clients?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203212#M4182</link>
      <description>&lt;P&gt;Thats true, thats why I found it a bit odd when TAC told me that was related to remote access, but maybe as it was under remote access section, not sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 12:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203212#M4182</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-16T12:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Disable weak ciphers on remote access clients?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203238#M4183</link>
      <description>&lt;P&gt;You may find this SK helpful which details how to completely banish 3DES from being used in any part of the Check Point product including Remote Access VPN, Gaia Portal, management API, etc.&amp;nbsp; This is mentioned in my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_blank" rel="noopener"&gt;Gateway Performance Optimization&lt;/A&gt; class as improving performance, but certainly improves security as well:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk113114" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk113114: Check Point response to CVE-2016-2183 (Sweet32)&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Might be able to deconstruct the provided commands and banish SHA1 and other weak ciphers too.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:01:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Disable-weak-ciphers-on-remote-access-clients/m-p/203238#M4183</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-01-16T15:01:05Z</dc:date>
    </item>
  </channel>
</rss>

