Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
kiriwaEvariste
Participant

Disabling TLS 1.0 and TLS 1.1 on Quantum Spark 1555

Hello community,
How do I disable TLS1.0 and TLS1.1 on Quantum Spark devices in CLI with version R81.10.10 ?

0 Kudos
7 Replies
Lesley
MVP Gold
MVP Gold

VPN? Syslog? Gaia portal? SSH? HTTPS inspection?

SSL inspection try:

https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/CLI/EN/Content/Topics/set-adm...

SSH:

https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/CLI/EN/Content/Topics/show-ss...

webui try:

  1. Enter Clish mode.

    clish

  2. Run:

    set admin-access support-weak-tls-version false

  3. Save the changes in the database:

    save config

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
kiriwaEvariste
Participant

Thanks, that was helpful.
However, is there a command to disable it generally in the LAN so that it's not just SSH and the web portal, but all services using TLS 1.0 and TLS 1.1 are blocked?

 

0 Kudos
Lesley
MVP Gold
MVP Gold

you mean clients that sends TLS 1.0 you want to block? Or you want to block TLS 1.0 on the fw itself? 

So traffic that flows via this firewall , like browsing traffic?

Then you need security blades likes IPS and application control to block old TLS versions. 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
kiriwaEvariste
Participant

We want to block clients that send TLS 1.0.
We have the IPS module.
How can we specifically block TLS 1.0 and TLS 1.1 with IPS?

0 Kudos
Lesley
MVP Gold
MVP Gold

With app control: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

Recommended way is with https inspection:

https://support.checkpoint.com/results/sk/sk182224

IPS: search for IPS protections TLS 1.0 and TLS 1.1 overwrite protection with drop instead of accept / inactive -> https://support.checkpoint.com/results/sk/sk179910

Generic info:

https://support.checkpoint.com/results/sk/sk178505

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
kiriwaEvariste
Participant

Thanks,

But it's an SMB that is managed locally, so this procedure will be difficult to implement.
And writing a rule with port 443 on SMBs, I'm afraid it will block other services using that port. That's why I was looking for a command that could disable TLS1.0 and TLS1.1 so that a user couldn't use a service using TLS1.0 and TLS1.0.

0 Kudos
Lesley
MVP Gold
MVP Gold

Start a test rule with only 1 machine (IP) , test with SSL labs (browser test) to compare results.

For ips start with: https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/View...

try to find tls in application database for app control

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events