<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5508-x unable to set TLSv1.2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5508-x-unable-to-set-tlsv1-2/m-p/4619263#M1090453</link>
    <description>&lt;P&gt;Hi guys, I have an ASA-5508X w/ firepower that I recently upgraded to the latest recommended version 9.16(2)14.&amp;nbsp; We are using Anyconnect and a recent security audit detected that TLS 1 and 1.1 are allowed on the outside IP.&amp;nbsp; Using the latest ASDM 7.16(1)150 I can see that under SSL settings it is set to use TLS v1 as the minimum version as a server and DTLSV1.&amp;nbsp; I'm aware that the 5508 does not support DTLSv1.2, however when I try to change the minimum TLS version to 1.2 I get the below error.&amp;nbsp; Any ideas why?&amp;nbsp; I should be able to use TLS1.2 along with DTLSv1 no?&lt;/P&gt;&lt;PRE&gt;[ERROR] ssl server-version tlsv1.2 dtlsv1
	
ssl server-version tlsv1.2 dtlsv1
                  ^
ERROR: % Invalid input detected at '^' marker.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 May 2022 13:15:27 GMT</pubDate>
    <dc:creator>kgula</dc:creator>
    <dc:date>2022-05-27T13:15:27Z</dc:date>
    <item>
      <title>ASA5508-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-x-unable-to-set-tlsv1-2/m-p/4619263#M1090453</link>
      <description>&lt;P&gt;Hi guys, I have an ASA-5508X w/ firepower that I recently upgraded to the latest recommended version 9.16(2)14.&amp;nbsp; We are using Anyconnect and a recent security audit detected that TLS 1 and 1.1 are allowed on the outside IP.&amp;nbsp; Using the latest ASDM 7.16(1)150 I can see that under SSL settings it is set to use TLS v1 as the minimum version as a server and DTLSV1.&amp;nbsp; I'm aware that the 5508 does not support DTLSv1.2, however when I try to change the minimum TLS version to 1.2 I get the below error.&amp;nbsp; Any ideas why?&amp;nbsp; I should be able to use TLS1.2 along with DTLSv1 no?&lt;/P&gt;&lt;PRE&gt;[ERROR] ssl server-version tlsv1.2 dtlsv1
	
ssl server-version tlsv1.2 dtlsv1
                  ^
ERROR: % Invalid input detected at '^' marker.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 13:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-x-unable-to-set-tlsv1-2/m-p/4619263#M1090453</guid>
      <dc:creator>kgula</dc:creator>
      <dc:date>2022-05-27T13:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-x-unable-to-set-tlsv1-2/m-p/4620067#M1090480</link>
      <description>&lt;P&gt;Can you conform that you have the 3DES-AES license installed?&lt;/P&gt;
&lt;P&gt;My ASA 5506-x with a slightly older version does support the TLS1.2 setting:&lt;/P&gt;
&lt;PRE&gt;asa5506-lab# sh run boot
boot system disk0:/asa9-15-1-7-lfbff-k8.SPA
asa5506-lab# sho ver | i AES
Encryption-3DES-AES               : Enabled        perpetual
asa5506-lab# sh run | i server-version
ssl server-version tlsv1.2
asa5506-lab#&lt;/PRE&gt;
&lt;P&gt;I updated it since it's just a lab ASA and it still supports 1.2:&lt;/P&gt;
&lt;PRE&gt;asa5506-lab# sh ver | i SPA   
System image file is "disk0:/asa9-16-2-14-lfbff-k8.SPA"
asa5506-lab# sh run | i server-version
ssl server-version tlsv1.2
asa5506-lab#&lt;/PRE&gt;</description>
      <pubDate>Mon, 30 May 2022 04:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-x-unable-to-set-tlsv1-2/m-p/4620067#M1090480</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-05-30T04:08:23Z</dc:date>
    </item>
  </channel>
</rss>

