Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
John_Fenoughty
Collaborator

Cloning Group Nessus and SSLv3

Hi Check Mates,

 

I have been looking through a Nessus Scan of a gateway cluster today, I had allowed all ports for the scanner to the gateways and turned off IPS for it.

The gateway version is R81.20 Jumbo hotfix 92

Nessus is complaining about the existence of SSLv3 and some weak ciphers. We disabled SSLv3 years ago and get an A+ from the Qualys SSL scanner online.

Then I noticed that it is Port TCP/1129 that is accepting SSLv3 (and 2) see the screenshot. This is of course the cloning group port.

I have searched the KB and these pages and cannot find any mention of this, has anyone else seen this and do we know how to get the cloning group comms onto TLS1.2?

 
 

 

Thanks,

John

0 Kudos
1 Reply
Lesley
Mentor Mentor
Mentor

https://support.checkpoint.com/results/sk/sk182091

PRJ-43614,
PRHF-26959

Gaia OS

UPDATE: Gaia Cloning Groups will now use the highest TLS version available.

 

Strange should already be fixed. Best way is to make Wireshark capture and use the SK above to see if it is really SSLV3 or maybe false positive. If not open a TAC case with the capture.

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events