- CheckMates
- :
- Products
- :
- General Topics
- :
- Monitor TLS versions outbound and inbound traffic ...
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Monitor TLS versions outbound and inbound traffic passing through a gateway
Is there a recommended way to monitor which connections are using TLS1.0 / TLS1.1 / TLS 1.2 ?
Does SSL inspection have to be enabled for TLS traffic analysis ?
Use case: If we have to make TLSv1.2 mandatory we would like to know the current usage of all the versions.
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe there are IPS signatures for the various TLS versions.
You can enable them in detect mode to see which clients are using them.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does SSL inspection have to be enabled for TLS traffic analysis ?
No, but you need AppControl. There are predefined Services for TLS1.0 to TLS1.2. I had to manually enable the protocol signature in the advanced tab of the serivce, so check that before installation.
