Greetings Mates!!
We recently had a vulnerability scan in a firewall cluster (two Check Point 6200, OS Gaia R81 Build 392)
The result of this vulnerability scan shows the following:
- Secure Sockets Layer/Transport Layer Security (SSL/TLS) Server Supports Transport Layer Security (TLSv1.1)
- Secure Sockets Layer/Transport Layer Security (SSL/TLS) Server Supports Transport Layer Security (TLSv1.0)
I tried checking previous solutions for this, but they show disabling or selecting TLSv1.2 from the SmartConsole->Global Properties section. The thing is, we have several other firewalls and firewall clusters in the SmartConsole, so making this change would affect not only the firewalls that were scanned, but the other firewalls managed in the console.
Is there a way we can disable TLSv1.0 and TLSv1.1, and enabling TLSv1.2 in just the firewalls we need?