<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072642#M1069445</link>
    <description>&lt;P&gt;6.6 also does not allow this change from FDM/CDO. We have to wait until those settings are API-enabled.&lt;/P&gt;
&lt;P&gt;Fingers crossed for 6.7 (Fall 2020) but time will tell.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2020 17:10:26 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-04-23T17:10:26Z</dc:date>
    <item>
      <title>Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072356#M1069427</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;I am running a VPN headend with FDM on ASA 5516-X box. FDM is the customer preferred choice as it has GUI and he is not interested in going back to ASA image. Recently we had&amp;nbsp;an&amp;nbsp;&lt;SPAN&gt;email from customer after having a vulnerability assessment done against his environment. below are the outcomes. Any support will be helpful&amp;nbsp;to address this&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;TLS/SSL Server Supports The Use of Static Key Ciphers&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;TLS/SSL Server is enabling the BEAST attack&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;TLS Server Supports TLS version 1.1&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;TLS Server Supports TLS version 1.0&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 23 Apr 2020 13:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072356#M1069427</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2020-04-23T13:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072366#M1069428</link>
      <description>&lt;P&gt;&lt;SPAN&gt;TLS 1.0 and 1.1 are considered vulnerable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;recommended is TLS 1.2 or 1.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 13:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072366#M1069428</guid>
      <dc:creator>omz</dc:creator>
      <dc:date>2020-04-23T13:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072399#M1069430</link>
      <description>&lt;P&gt;I am totally aware of it mate, the biggest worry is I dont find an option to disable it in the GUI, Firepower or Lina CLI. Any idea whether this can be done in linux level?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 14:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072399#M1069430</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2020-04-23T14:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072412#M1069432</link>
      <description>&lt;P&gt;The commands necessary to restrict SSL/TLS ciphersuites are not currently available for FDM (or CDO) managed Firepower devices. Also, you cannot add them via Flexconfig (blacklisted).&lt;/P&gt;
&lt;P&gt;If you use FMC management, the settings can be changed under Devices &amp;gt; Platforms Settings &amp;gt; SSL. See the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FMC SSL settings for FTD.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72708i226E29DCDE8F6EF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC SSL settings for FTD.PNG" alt="FMC SSL settings for FTD.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 14:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072412#M1069432</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-23T14:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072432#M1069434</link>
      <description>&lt;P&gt;Thanks Marvin. I am currently in 6.5.04. Any idea on 6.6.0? Not related to the subject, but how is the SBL support for anyconnect FDM or Firepower?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 14:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072432#M1069434</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2020-04-23T14:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072642#M1069445</link>
      <description>&lt;P&gt;6.6 also does not allow this change from FDM/CDO. We have to wait until those settings are API-enabled.&lt;/P&gt;
&lt;P&gt;Fingers crossed for 6.7 (Fall 2020) but time will tell.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 17:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4072642#M1069445</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-23T17:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4073663#M1069503</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm experiencing the same issue with our FTD AnyConnect website. I opened a service ticket earlier this year but the explanation was a little different at the time. Are you saying that currently a Cisco's security product is vulnerable and they don't have any plans to fix this issue until November?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 19:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4073663#M1069503</guid>
      <dc:creator>aswit</dc:creator>
      <dc:date>2020-04-24T19:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4290331#M1078418</link>
      <description>&lt;P&gt;anybody figured how to do that?&lt;/P&gt;&lt;P&gt;running 6.7 ngfw2110 with fdm and can't set the tls to tlsv1.2&lt;/P&gt;&lt;P&gt;can't find what flex config i can use for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;works fine in firesight managed devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 18:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4290331#M1078418</guid>
      <dc:creator>loizosko</dc:creator>
      <dc:date>2021-02-11T18:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4290342#M1078419</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/254424"&gt;@loizosko&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like you can do this in FDM 6.7 using API.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ssl ciphers.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104216iBB91C2BD654AC43B/image-size/large?v=v2&amp;amp;px=999" role="button" title="ssl ciphers.PNG" alt="ssl ciphers.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You don't appear to be able to make changes using flexconfig using 6.7, the CLI commands are currently blacklisted.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 19:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4290342#M1078419</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-02-11T19:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4314629#M1079679</link>
      <description>&lt;P&gt;From Cisco:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using a FDM it’s not possible to enable FIPS. This is a known issue.&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp07593/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp07593/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 17:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4314629#M1079679</guid>
      <dc:creator>IvanAlvarenga25979</dc:creator>
      <dc:date>2021-03-26T17:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4314891#M1079706</link>
      <description>&lt;P&gt;This FDM shortcoming will be addressed in version 7.0 (the next release after 6.7). It's in the GUI there.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Mar 2021 14:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4314891#M1079706</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-03-27T14:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Weak Ciphers for SSL VPN in Firepower FDM</title>
      <link>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4588550#M1089045</link>
      <description>&lt;P&gt;In FDM this can be configured from System Settings -&amp;gt; SSL Settings.&lt;BR /&gt;The feature is available for version 7.0+.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 18:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-weak-ciphers-for-ssl-vpn-in-firepower-fdm/m-p/4588550#M1089045</guid>
      <dc:creator>rtahirov</dc:creator>
      <dc:date>2022-04-07T18:45:20Z</dc:date>
    </item>
  </channel>
</rss>

