Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
bhill3
Explorer

Enabling TLS 1.3 for All Gateway Interfaces

We are trying to ensure that TLS 1.3 is enabled on our Checkpoint Gateways and have successfully configured the primary interface of the Gateways to have TLS 1.3 enabled (as well as disable TLS 1.0 & TLS 1.1) by using the following clish commands:

show ssl tls enabled
set ssl tls TLSv1.0 off  # repeat as needed with other TLS versions
set ssl tls TLSv1.3 on
save config

This seems to have only applied to the primary interface of the Gateway. Is there a way that we can also ensure that TLS 1.3 is enabled for the secondary interface of the Gateway? Specifically we're looking to enable TLS 1.3 for port 443.

Thanks!

0 Kudos
3 Replies
Lesley
MVP Platinum
MVP Platinum

https://support.checkpoint.com/results/sk/sk178505

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
the_rock
MVP Diamond
MVP Diamond

From expert mode -> cipher_util, option 2, then 2 again, follow the prompts.

Best,

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Daniel_Kavan
MVP Gold
MVP Gold

Per sk178505, it doesn't mention TLS 1.3 for R82.10    Also, it looks like TLS 1.2 is the max (not TLSv1.3) for remote access (mobile).  see Remote Access VPN - SNX in Network Mode / Slim Client section in sk178505.  Any one have an ETA or know if it's being looked at for Mobile Access?  Qualys scans give us an A- now.  😞

cipher_util just shows and option for TLS 1.2, even after turning 1.3 on. set ssl tls TLSv1.3 on save config

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events