Hi Check Mates,
I have been looking through a Nessus Scan of a gateway cluster today, I had allowed all ports for the scanner to the gateways and turned off IPS for it.
The gateway version is R81.20 Jumbo hotfix 92
Nessus is complaining about the existence of SSLv3 and some weak ciphers. We disabled SSLv3 years ago and get an A+ from the Qualys SSL scanner online.
Then I noticed that it is Port TCP/1129 that is accepting SSLv3 (and 2) see the screenshot. This is of course the cloning group port.
I have searched the KB and these pages and cannot find any mention of this, has anyone else seen this and do we know how to get the cloning group comms onto TLS1.2?
Thanks,
John