All things Palo Alto Networks

  • Blog

  • Forum

  • Members

  • More

    Use tab to navigate through the menu items.
    To see this working, head to your live site.
    • Categories
    • All Posts
    • My Posts
    vijaya.vasan
    Dec 08, 2021

    Security Advice on SSH & SSL/TLS week ciphers

    in General discussion

    I have few queries to be addressed.

    We have changed the SSL/TLS version using CLI to TLS 1.2 but when we run the scan we can see TLS 1.1 is also running at the back-end. We need to check which SSL/TLS version is running using CLI of the Firewall.

    What command needs to be used to check the current TLS version of the firewall? in CLI

    Secondly:

    We need to know which SSL/TLS cipher is recommended. From our security team point of view we need to disable the below mentioned ciphers (DH & RSA) algorithms. If we disable these two will there be any issue?

    How to disable them? Steps and commands to disable through CLI?

    Will the firewall work intended even after disabling DH and RSA?

    What are the recommended SSL/TLS cipher for the firewall?

    Thirdly:

    We need to know what is the current SSH Cipher its taking for the SSH of the firewall how to find which one is currently being used.

    Let me know on the above

    Cheers!

    0 comments
    0
    Comments
    0 comments
    Similar Posts
    • Recommended SSL/TLS Settings
    • Sweet32,3DES, SHA1,RC4, disable, using "RSA certificate" with SSL/TLS profile
    • Certificate doubt for Web Management GUI-SSL/TLS - Palo Alto Firewalls HA Active-Passive
     
    • Mastering Palo Alto Networks
    • PANgurus LinkedIn

    Subscribe Form

    Privacy Policy

    Terms of use

    ©2020 by PANgurus.