Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TG_Mai
Explorer

Disable CBC mode cipher and enable GCM cipher mode for https inspection

hello 

we have R80.10 with https inspection on, does anyone know how to disable the CBC mode cipher for TLS_ECDHE_RSA * in the https inspection?

There an SK show how to allow specific cipher suites only for VPN in R80.10

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

any help would be great, thank you.

TG

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Note that if you're using HTTPS Inspection, it's a good idea to upgrade to R80.30 as it supports additional ciphers, has a better utility to configure what it supported/allowed, and improved SNI support.
0 Kudos
Suresh_Kumar
Explorer

We have already on R80.30 and we are facing the same issue that the all CBC Cipher are showing enable for all the application.

Is there any way to restrict ciphers for specific natted IP?

0 Kudos