Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
D_Riddleberger
Collaborator
Collaborator

PCI Scans Failing and Disablement of DES and DH Group 1

I have a site where PCI Scans are failing for DES and DH Group 1 vulnerabilities.

I'm pretty sure that we can disable DES exposure in Cluster>IPSEC VPN>Traditional Mode>General Properties (see pic) while following sk82900

https://support.checkpoint.com/results/sk/sk82900.

But in same pane/pic for Advanced Properties, it lists all the supported DH Groups and DH-1 Group is not selected.

So I need a document or sk for how/why DH Group-1 is being detected and how to disable it

 

cm-cluster-ipsec-props-1.png

 

6 Replies
Lesley
MVP Gold
MVP Gold

Maybe worth to check also here 

image.png

-------
Please press "Accept as Solution" if my post solved it 🙂
Lesley
MVP Gold
MVP Gold

Are the results maybe from a GAIA embedded unit? then check out

https://support.checkpoint.com/results/sk/sk184658

-------
Please press "Accept as Solution" if my post solved it 🙂
D_Riddleberger
Collaborator
Collaborator

Hi Lesley,

 

No, these are not embedded Gaia SMB Appliances.

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

You may also wish to review sk113114 more broadly

CCSM R77/R80/ELITE
D_Riddleberger
Collaborator
Collaborator

Hi Chris,

Yes, that sk does provide some additional insight. Thank You.

I have confirmed that DES as well DH Group-1 is not used in any VPN Communities. As I did not think that it was. The problem is that the gateways are 'responding to' some level of acknowledgement/response from the scan that features/functionality for DES and DH Group 1 are enabled. I also confirmed from the scan report that it is IPSEC that is being flagged. So, I think we are in the clear for DES and DH Group 1 when it comes to SSH and Remote Access features/functionality whereas those can be turned off in Global Properties>Remote Access>VPN Auth and Encryption <edit algorithms>. I'm still digging....

the_rock
MVP Diamond
MVP Diamond

Hey Dan,

Seems like you have it all configured properly. Might be worth TAC case to confirm, for sure. I did check in smart console and all the settings you mentioned are 100% right.

Best,
Andy
"Have a great day and if its not, change it"

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events