Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SerDiHer0411
Explorer

Secure Sockets Layer/Transport Layer Security (SSL/TLS) Server supports Transport Layer Security

Greetings Mates!!

We recently had a vulnerability scan in a firewall cluster (two Check Point 6200, OS Gaia R81 Build 392)

The result of this vulnerability scan shows the following:

-  Secure Sockets Layer/Transport Layer Security (SSL/TLS) Server Supports Transport Layer Security (TLSv1.1)

-  Secure Sockets Layer/Transport Layer Security (SSL/TLS) Server Supports Transport Layer Security (TLSv1.0)

I tried checking previous solutions for this, but they show disabling or selecting TLSv1.2 from the SmartConsole->Global Properties section. The thing is, we have several other firewalls and firewall clusters in the SmartConsole, so making this change would affect not only the firewalls that were scanned, but the other firewalls managed in the console.

 

Is there a way we can disable TLSv1.0 and TLSv1.1, and enabling TLSv1.2 in just the firewalls we need?

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Unfortunately, all Global Properties settings applies to all gateways managed in that same domain.
Did you try making changes in cipher_util first? https://support.checkpoint.com/results/sk/sk126613 
These are local to the gateway.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events