<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommend Cipher Suites in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4060298#M1068898</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;let's ask an expert -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope Marvin can comment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Apr 2020 19:16:52 GMT</pubDate>
    <dc:creator>omz</dc:creator>
    <dc:date>2020-04-06T19:16:52Z</dc:date>
    <item>
      <title>Recommend Cipher Suites</title>
      <link>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4059798#M1068843</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking at hardening the https server for a number of Cisco devices including IOS-XE for Cat9k switches and WLC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the devices I can see that the following Cipher Suites can be supported but I'm not sure what the current recommendations are. Are there any from the list that are recommended and ones that should be avoided?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3des-ede-cbc-sha Encryption type tls_rsa_with_3des_ede_cbc_sha ciphersuite&lt;BR /&gt;aes-128-cbc-sha Encryption type tls_rsa_with_aes_cbc_128_sha ciphersuite&lt;BR /&gt;aes-256-cbc-sha Encryption type tls_rsa_with_aes_cbc_256_sha ciphersuite&lt;BR /&gt;dhe-aes-128-cbc-sha Encryption type tls_dhe_rsa_with_aes_128_cbc_sha ciphersuite&lt;BR /&gt;dhe-aes-cbc-sha2 Encryption type tls_dhe_rsa_with_aes_cbc_sha2(TLS1.2 &amp;amp; above) ciphersuite&lt;BR /&gt;dhe-aes-gcm-sha2 Encryption type tls_dhe_rsa_with_aes_gcm_sha2(TLS1.2 &amp;amp; above) ciphersuite&lt;BR /&gt;ecdhe-ecdsa-aes-gcm-sha2 Encryption type tls_ecdhe_ecdsa_aes_gcm_sha2 (TLS1.2 &amp;amp; above) SuiteB ciphersuite&lt;BR /&gt;ecdhe-rsa-3des-ede-cbc-sha Encryption type tls_ecdhe_rsa_3des_ede_cbc_sha ciphersuite&lt;BR /&gt;ecdhe-rsa-aes-128-cbc-sha Encryption type tls_ecdhe_rsa_with_aes_128_cbc_sha ciphersuite&lt;BR /&gt;ecdhe-rsa-aes-cbc-sha2 Encryption type tls_ecdhe_rsa_aes_cbc_sha2(TLS1.2 &amp;amp; above) ciphersuite&lt;BR /&gt;ecdhe-rsa-aes-gcm-sha2 Encryption type tls_ecdhe_rsa_aes_gcm_sha2(TLS1.2 &amp;amp; above) ciphersuite&lt;BR /&gt;rsa-aes-cbc-sha2 Encryption type tls_rsa_with_aes_cbc_sha2(TLS1.2 &amp;amp; above) ciphersuite&lt;BR /&gt;rsa-aes-gcm-sha2 Encryption type tls_rsa_with_aes_gcm_sha2(TLS1.2 &amp;amp; above) ciphersuite&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 10:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4059798#M1068843</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2020-04-06T10:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Recommend Cipher Suites</title>
      <link>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4059825#M1068846</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;This doc explains and shows the acceptable cipher suites to give you some idea. Use tls 1.2, highest sha and aes where supported.&lt;/P&gt;&lt;P&gt;&lt;A href="https://tools.cisco.com/security/center/resources/next_generation_cryptography" target="_blank" rel="noopener"&gt;https://tools.cisco.com/security/center/resources/next_generation_cryptography&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-04-06 at 12.01.40.png" style="width: 397px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/70864i273B11EA93D9B924/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2020-04-06 at 12.01.40.png" alt="Screenshot 2020-04-06 at 12.01.40.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 11:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4059825#M1068846</guid>
      <dc:creator>omz</dc:creator>
      <dc:date>2020-04-06T11:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Recommend Cipher Suites</title>
      <link>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4060009#M1068863</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the response. From what I can see the following ciphers are for tls v1.2 and above and meet Cisco's recommendation of using AES GSM as the the encryption algorithms. Does this look right to you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rsa-aes-gcm-sha2&lt;/P&gt;&lt;P&gt;dhe-aes-gcm-sha2&lt;/P&gt;&lt;P&gt;ecdhe-rsa-aes-gcm-sha2&lt;/P&gt;&lt;P&gt;ecdhe-ecdsa-aes-gcm-sha2&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 15:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4060009#M1068863</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2020-04-06T15:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Recommend Cipher Suites</title>
      <link>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4060298#M1068898</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;let's ask an expert -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope Marvin can comment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 19:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4060298#M1068898</guid>
      <dc:creator>omz</dc:creator>
      <dc:date>2020-04-06T19:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Recommend Cipher Suites</title>
      <link>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4060713#M1068917</link>
      <description>&lt;P&gt;Which ciphers you disable depends on more than just which are the most secure. Often there are larger issues at play such as client compatibility. You need to analyze your environment for such issues. Sometimes in our zeal to make the devices as secure as possible we can inadvertently deny service to legitimate infrastructure users or services thus making the "cure" worse than the "disease".&lt;/P&gt;
&lt;P&gt;First ask yourself what are you using the https server for. If it's not in use then simply disable it. If it is in use, what are the clients - e.g. a few other infrastructure devices and applications or a larger end user base? In either case, consider carefully and test compatibility before committing to supporting only the strongest ciphers.&lt;/P&gt;
&lt;P&gt;If all your analysis checks out then narrow things down to the strongest mutually compatible ciphersuite - e.g., the Suite B one.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 10:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommend-cipher-suites/m-p/4060713#M1068917</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-07T10:08:51Z</dc:date>
    </item>
  </channel>
</rss>

