<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5516-x unable to set TLSv1.2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4691844#M1093568</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/89946"&gt;@Alex Ribas&lt;/a&gt; TLS 1.2 is supported on the 5516, but DTLS 1.2 is not. In your output above you've set - "ssl server-version tlsv1.2 dtlsv&lt;STRONG&gt;1.2" &lt;/STRONG&gt;&amp;lt; change that to DTLS 1.0.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2022 09:08:58 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-09-22T09:08:58Z</dc:date>
    <item>
      <title>ASA5516-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4691842#M1093567</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;We have an ASA-5516X with the latest recommended version 9.16(2). I get the below error. I should be able to use TLS1.2 along with DTLSv1 no?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ssl server-version tlsv1.2 ?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;configure mode commands/options:&lt;BR /&gt;&amp;lt;cr&amp;gt;&lt;BR /&gt;ssl server-version tlsv1.2 dtlsv1.2&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;
&lt;P&gt;xxxxxxxxxx3# sh run boot&lt;BR /&gt;boot system disk0:/asa9-16-2-lfbff-k8.SPA&lt;BR /&gt;xxxxxxxxxxx# sh ver | i AES&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;xxxxxx# sh ver | i server-version&lt;BR /&gt;xxxxxxxxx# sh run | i server-ve&lt;BR /&gt;ssl server-version tlsv1.2&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;AlexRibas&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 09:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4691842#M1093567</guid>
      <dc:creator>Alex Ribas</dc:creator>
      <dc:date>2022-09-22T09:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5516-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4691844#M1093568</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/89946"&gt;@Alex Ribas&lt;/a&gt; TLS 1.2 is supported on the 5516, but DTLS 1.2 is not. In your output above you've set - "ssl server-version tlsv1.2 dtlsv&lt;STRONG&gt;1.2" &lt;/STRONG&gt;&amp;lt; change that to DTLS 1.0.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 09:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4691844#M1093568</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-09-22T09:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5516-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692206#M1093596</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't have this option&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ssl server-version ?&lt;/P&gt;
&lt;P&gt;configure mode commands/options:&lt;BR /&gt;tlsv1 Enter this keyword to accept SSLv2 ClientHellos and negotiate TLSv1&lt;BR /&gt;(or greater)&lt;BR /&gt;tlsv1.1 Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;TLSv1.1 (or greater)&lt;BR /&gt;tlsv1.2 Enter this keyword to accept SSLv2 ClientHellos and negotiate&lt;BR /&gt;TLSv1.2 (or greater)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692206#M1093596</guid>
      <dc:creator>Alex Ribas</dc:creator>
      <dc:date>2022-09-22T16:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5516-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692209#M1093597</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/89946"&gt;@Alex Ribas&lt;/a&gt; ok, so just set ""ssl server-version tlsv1.2" the default and only version of DTLS 1.0 will be used.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692209#M1093597</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-09-22T16:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5516-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692220#M1093598</link>
      <description>&lt;P&gt;Yes but the point is we need use 1.2&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AlexRibas_0-1663863333740.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/163148i79E0FE2646C88B79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AlexRibas_0-1663863333740.png" alt="AlexRibas_0-1663863333740.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:15:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692220#M1093598</guid>
      <dc:creator>Alex Ribas</dc:creator>
      <dc:date>2022-09-22T16:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5516-x unable to set TLSv1.2</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692223#M1093599</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/89946"&gt;@Alex Ribas&lt;/a&gt; but like I said in the initial response, DTLS 1.2 is not supported on the 5516.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html#id_25471" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html#id_25471&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;"DTLS 1.2, as defined in RFC- 6347, is now supported for AnyConnect remote access in addition to the currently supported DTLS 1.0 (1.1 version number is not used for DTLS.) This applies to all ASA models &lt;STRONG&gt;except&lt;/STRONG&gt; the 5506-X, 5508-X, and &lt;STRONG&gt;5516-X"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;So you can only use TLS 1.2 and DTLS 1.0 on the 5516, you'd have to replace the hardware to be able to use DTLS 1.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-x-unable-to-set-tlsv1-2/m-p/4692223#M1093599</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-09-22T16:20:53Z</dc:date>
    </item>
  </channel>
</rss>

