- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm trying to track down how to get legacy client authentication to disable SSLv2/v3 TLS1.0 and TLS1.1. I found
sk102989 - Check Point response to the POODLE Bites vulnerability (CVE-2014-3566)
and
sk100584 - Cipher strength for Client Authentication feature is under 128-bit and there is no way to control which SSL version to use
both basically say to set ASSL_NO_SSLV2=1 and ASSL_NO_SSLV3=1 (how they say to set them is a little different but end result looks the same).
However sk100584 also says how to disable TLS1.0 (but not TLS 1.1 ?) but also says you can't disable all three.
I'm a little confused what is the proper way to disable the insecure protocols here. My goal would be to only support TLS1.2 for client auth. Yes, I know captive portal would be better but we're not in a place where we can move everything yet.
As you probably know, Client Auth is a legacy feature.
Not sure if fixing Client Auth falls under @Royi_Priov ’s team or not.
That said, understanding the precise use case for Client Auth may be useful so we can make Identity Awareness support it.
@Nachum_Moshe can you please assist?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY