Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TG_Mai
Explorer

Disable CBC mode cipher and enable GCM cipher mode for https inspection

hello 

we have R80.10 with https inspection on, does anyone know how to disable the CBC mode cipher for TLS_ECDHE_RSA * in the https inspection?

There an SK show how to allow specific cipher suites only for VPN in R80.10

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

any help would be great, thank you.

TG

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Note that if you're using HTTPS Inspection, it's a good idea to upgrade to R80.30 as it supports additional ciphers, has a better utility to configure what it supported/allowed, and improved SNI support.
0 Kudos
Suresh_Kumar
Explorer

We have already on R80.30 and we are facing the same issue that the all CBC Cipher are showing enable for all the application.

Is there any way to restrict ciphers for specific natted IP?

0 Kudos
Zatimus
Explorer

Hi Suresh,

Hope you are doing well. Want to ask, you manage to have your questions answered? if you do could you share with me the steps.

Thank you

0 Kudos
G_W_Albrecht
Legend
Legend

A good starting point is sk104562: Supported cipher suites for HTTPS Inspection that lists supported ciphers for many versions. Then use sk126613: Cipher configuration tool for Security Gateways to configure it as requested.

CCSE CCTE CCSM SMB Specialist
0 Kudos
tavi0906
Participant

is there any way to block the CBC ciphers on a NAT ip

 

0 Kudos
G_W_Albrecht
Legend
Legend

Please explain - what is a NAT IP for you? Usually, allowed ciphers can be set for SSH, SSL VPN and Multiportal.

CCSE CCTE CCSM SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events