Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
P_Williams
Contributor
Jump to solution

Resolving TLS1.0 and TLS1.1 Security Threats for Remote Access

I have been sent a report listing various public facing services on our firewalls and whether they are allowing TLS1.0 and TLS1.1.

For the URL that clients use to connect to use the Remote Access vpn it has come back as allowing 1.0 and 1.1

Risk VectorFinding IdentifierLast SeenGradeAttributed ToFinding Severity
SSL Configurationsremoteaccess.mycompany.com:44327/03/2025BADMy Company Inc.severe
Asset ImportanceAssetsDetails
criticalremoteaccess.mycompany.comAllows insecure protocol: TLSv1.0; Allows insecure protocol: TLSv1.1

 

Presumably the client, when it connects initially, wouldn't be using 1.0 or 1.1. But beyond that I don't know what I can do to get rid of the vulnerability. I am not sure if the vulnerability even is to do with the RemoteAccess service, it is just that it uses the same public IP as the firewalls.

What could I do on the firewall to remove this vulnerability?

The firewalls are VSX running r81

0 Kudos
1 Solution

Accepted Solutions
G_W_Albrecht
MVP Silver
MVP Silver
8 Replies
G_W_Albrecht
MVP Silver
MVP Silver
0 Kudos
P_Williams
Contributor

That looks promising, many thanks. Looks like it will need a proper review and CAB before implementing but will feedback how I get on.

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

It is just an advanced Portal configuration option in SmartDashboard menue, see the screenshot @the_rock has posted.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
P_Williams
Contributor

Hi,

Just confirming that this worked, we changed the setting to 1.2 and the vulnerability scan has now succeeded. Thank you

0 Kudos
the_rock
MVP Gold
MVP Gold

Hey @P_Williams 

I believe you can also correct this with settings I attached from global properties.

Andy

 

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

Yes, found here: sk154532: Vulnerability scan detects that the Security Gateway supports TLS 1.0 or TLS 1.1 when one ...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
the_rock
MVP Gold
MVP Gold

Sorry, my bad, it asked me to log in to view that sk when I tried yesterday, but I see it now.

Andy

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

You did post the shortcut 🙃

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events