- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Vulnerability Mitigation for TLS 1.0 and Weak ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Vulnerability Mitigation for TLS 1.0 and Weak Ciphers
Hello,
I need instructions to mitigate the following two vulnerabilities from our Gateways :
1) Enable Support for TLS 1.1 and TLS 1.2 , and disable TLS 1.0
2) Removal of Weak Ciphers
We are using a VSX Cluster environment with R80.10
Also, what could be the after effects after removing these vulnerabilities on the existing production environment.
Please suggest.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The main one the comes up (Gaia WEBUI) isn't relevant on VSX.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Like I said, the main culprit (the Gaia WebUI) is not active on VSX.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe also SSL Inspection ? Then see sk126613: Cipherconfiguration tool for R80.x Gateways.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
how to remediate TLS vulnerability on checkpoint firewall Virtual interface
and sk126613: Cipherconfiguration tool for R80.x Gateways. is not clearing this requirement @
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1) Enable Support for TLS 1.1 and TLS 1.2 , and disable TLS 1.0
Note: I am a novice user, so please check in test setup before applying to production.
Solution: In Smart console menu->Global properties->Advanced->Configure...
Go to portal properties, there it will show option to set max and min ssl version attributes.
There you may change ssl min. version from TLS1.0 to TLS1.1.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
awesome, thanks for sharing
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Follow -sk147272 , sk106031 to mitigate the above vulnerability.
