<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disabling TLS 1.1 on Windows Client in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685960#M1093335</link>
    <description>&lt;P&gt;Hi Gurus,&lt;/P&gt;&lt;P&gt;I'm a software engineer by trade. I've been assigned the task to verify our applications able to work after disabling TLS 1.1 on Windows 10 Enterprise Edition client machines. Customer will be moving on to TLS 1.2.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Some details&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;AnyConnect client 4.10.01075&lt;BR /&gt;Cisco FTD 1120&lt;BR /&gt;Cisco FMC for VMWare. Software Version 6.4.0.12 (Build 112)&lt;BR /&gt;&lt;BR /&gt;My understanding on the requirements for DTLS v1.2 support&lt;BR /&gt;1. AnyConnect client version 4.7 and above&lt;BR /&gt;2. Cisco FMC version 6.6 and above&lt;BR /&gt;&lt;BR /&gt;Will disabling TLS 1.1 on Windows 10 machine affect our setup? Will it prevents AnyConnect client 4.10.0175 from connecting and establishing the VPN connection?&lt;BR /&gt;&lt;BR /&gt;TIA for any response.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Sep 2022 08:02:10 GMT</pubDate>
    <dc:creator>tankenghua</dc:creator>
    <dc:date>2022-09-13T08:02:10Z</dc:date>
    <item>
      <title>Disabling TLS 1.1 on Windows Client</title>
      <link>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685960#M1093335</link>
      <description>&lt;P&gt;Hi Gurus,&lt;/P&gt;&lt;P&gt;I'm a software engineer by trade. I've been assigned the task to verify our applications able to work after disabling TLS 1.1 on Windows 10 Enterprise Edition client machines. Customer will be moving on to TLS 1.2.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Some details&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;AnyConnect client 4.10.01075&lt;BR /&gt;Cisco FTD 1120&lt;BR /&gt;Cisco FMC for VMWare. Software Version 6.4.0.12 (Build 112)&lt;BR /&gt;&lt;BR /&gt;My understanding on the requirements for DTLS v1.2 support&lt;BR /&gt;1. AnyConnect client version 4.7 and above&lt;BR /&gt;2. Cisco FMC version 6.6 and above&lt;BR /&gt;&lt;BR /&gt;Will disabling TLS 1.1 on Windows 10 machine affect our setup? Will it prevents AnyConnect client 4.10.0175 from connecting and establishing the VPN connection?&lt;BR /&gt;&lt;BR /&gt;TIA for any response.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 08:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685960#M1093335</guid>
      <dc:creator>tankenghua</dc:creator>
      <dc:date>2022-09-13T08:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling TLS 1.1 on Windows Client</title>
      <link>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685971#M1093337</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1404186"&gt;@tankenghua&lt;/a&gt; you should be ok in just disabling TLS/DTLS 1.0 and 1.1 from the windows side, assuming you've upgraded the FMC and FTD to version 6.6 or higher (7.0.4 is the current Cisco gold star recommended version). You should consider configuring the FMC/FTD to not only require TLS/DTLS 1.2 but also to use the most secure ciphers, example &lt;A href="https://integratingit.wordpress.com/2021/01/28/secure-ftd-tls-ciphers/" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 08:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685971#M1093337</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-09-13T08:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling TLS 1.1 on Windows Client</title>
      <link>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685979#M1093339</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; Thank you for the prompt response and advise. Much appreciated.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My understanding from a former colleague the newer version of FMC is not supported on our ESXi version.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Our FMC is hosted on a legacy ESXi VMWare 5.1.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 08:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685979#M1093339</guid>
      <dc:creator>tankenghua</dc:creator>
      <dc:date>2022-09-13T08:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling TLS 1.1 on Windows Client</title>
      <link>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685983#M1093340</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1404186"&gt;@tankenghua&lt;/a&gt; yes that is accurate, for FMC 6.6 the minimum supported ESX version is 6.0.....in short you would need to upgrade your ESX environment to 6.X in order to use DTLS 1.2 which was released in 6.6.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/relnotes/firepower-release-notes-660/features.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/660/relnotes/firepower-release-notes-660/features.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 08:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disabling-tls-1-1-on-windows-client/m-p/4685983#M1093340</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-09-13T08:32:37Z</dc:date>
    </item>
  </channel>
</rss>

