- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
1. tell me, when you disable weak ciphers, you lose access to some old resources on the Internet or our services stop working from the Internet?
2. after configuring in Global Properties->Advanced->Configure…->Portal Properties, Are there any restrictions on the protocols with which Internet users can connect to our Remote Access Portal?
There is now information that some servers on the Internet are still using TLS 1.0. After completing this step, it will not be possible to connect to these servers through the Security Gateway, but I would like to study these issues in more detail
First: cipher_util can configure MultiPortal and/or SSL Inspection ciphers.
1. Not that i knew any ! Why should that be ?
2. Mobile Access or IPSec VPN should not be changed.
You can always connect to TLS 1.0 servers if you exclude the traffic from https inspection and use an old browser 😉
please specify,
1. By disabling weak ciphers, will we lose access to any old resources on the Internet that use TLS 1.0, but our services from the Internet will continue to work?
And also, can we resume their work by excluding the check in https inspection?
2. What is meant by this? Is it not recommended to disable ciphers when selecting (2) MultiPortal in cipher_util or what? In the portal properties there is no choice to disable for mobile access or ipsec vpn, it is disabled for all services at once
- if you disable weak ciphers for outbound https inspection, you can only reach TLS 1.0 by excluding the traffic from it
- if you disable weak ciphers for inbound https inspection, internal servers with TLS 1.0 can not be reached anymore
- if you disable weak ciphers for MultiPortal, GAiA, SmartView, SSLVPN a.o. portals can be reached as before
- IPSec has nothing to do with TLS 1.0
If you’re not using HTTPS Inspection, the configuration you make with cipher_util will have no effect on sites you connect to through the gateway.
If you have proper bypass rules in the HTTPS Inspection policy, those sites should still work.
It will definitely impact all connections to the gateway itself, including the Mobile Access Portal, but excluding IPsec VPN.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY