<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TLS Version 1.1 Protocol Deprecated in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851081#M1101352</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1482645"&gt;@taro75&lt;/a&gt; how are you managing the Firepower 2110, FDM or FMC? FDM is useless in regard to tweaking useful settings. You can define the TLS versions and encryption ciphers to use for &lt;STRONG&gt;remote access VPN connections in &lt;SPAN class="ph"&gt;FDM&lt;/SPAN&gt;&lt;/STRONG&gt;. Previously, you needed to use the &lt;SPAN class="ph"&gt;Firepower Threat Defense&lt;/SPAN&gt; API to configure SSL settings.&lt;/P&gt;
&lt;P class="p"&gt;Added in 7.0 - &lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Objects&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;SSL Ciphers&lt;/SPAN&gt;&lt;/SPAN&gt;; &lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Device&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;System Settings&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;SSL Settings&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P class="p"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21.png" style="width: 758px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186803i3CE9D88C33286F26/image-dimensions/758x572?v=v2" width="758" height="572" role="button" title="21.png" alt="21.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="p"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/relnotes/firepower-release-notes-700/features.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/relnotes/firepower-release-notes-700/features.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="p"&gt;Just unselect the protocols you no longer require.&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2023 08:24:15 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2023-06-08T08:24:15Z</dc:date>
    <item>
      <title>TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851076#M1101351</link>
      <description>&lt;P&gt;I am using Cisco Firepower 2110 with firmware 7.0.5-72 and the SSL 1.1 is in use.&lt;/P&gt;&lt;P&gt;How can I disable SSL 1.1 ?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Description&lt;/STRONG&gt;&lt;BR /&gt;The remote service accepts connections encrypted using TLS 1.1. TLS 1.1 lacks support for current and recommended cipher suites. Ciphers that support encryption before MAC computation, and authenticated encryption modes such as GCM cannot be used with TLS 1.1&lt;/P&gt;&lt;P&gt;As of March 31, 2020, Endpoints that are not enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.&lt;BR /&gt;Solution&lt;BR /&gt;Enable support for TLS 1.2 and/or 1.3, and disable support for TLS 1.1.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 08:04:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851076#M1101351</guid>
      <dc:creator>taro75</dc:creator>
      <dc:date>2023-06-08T08:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851081#M1101352</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1482645"&gt;@taro75&lt;/a&gt; how are you managing the Firepower 2110, FDM or FMC? FDM is useless in regard to tweaking useful settings. You can define the TLS versions and encryption ciphers to use for &lt;STRONG&gt;remote access VPN connections in &lt;SPAN class="ph"&gt;FDM&lt;/SPAN&gt;&lt;/STRONG&gt;. Previously, you needed to use the &lt;SPAN class="ph"&gt;Firepower Threat Defense&lt;/SPAN&gt; API to configure SSL settings.&lt;/P&gt;
&lt;P class="p"&gt;Added in 7.0 - &lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Objects&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;SSL Ciphers&lt;/SPAN&gt;&lt;/SPAN&gt;; &lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Device&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;System Settings&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;SSL Settings&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P class="p"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21.png" style="width: 758px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186803i3CE9D88C33286F26/image-dimensions/758x572?v=v2" width="758" height="572" role="button" title="21.png" alt="21.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="p"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/relnotes/firepower-release-notes-700/features.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/relnotes/firepower-release-notes-700/features.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="p"&gt;Just unselect the protocols you no longer require.&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 08:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851081#M1101352</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-06-08T08:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851083#M1101353</link>
      <description>&lt;P&gt;how you mgmt FMC or FDM ?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 08:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851083#M1101353</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-08T08:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851086#M1101354</link>
      <description>&lt;P&gt;I am using FDM and I can see the following SSL ciphers. I cannot edit the default SSL Cipher. I need to remove SSL 1.0 &amp;amp; 1.1&lt;/P&gt;&lt;P&gt;CiscoRecommendedCipher TLSv1.2 High&lt;BR /&gt;DefaultSSLCipher TLSv1.1, DTLSv1.0, DTLSv1.2, TLSv1.0, TLSv1.2 Medium&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 08:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851086#M1101354</guid>
      <dc:creator>taro75</dc:creator>
      <dc:date>2023-06-08T08:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851087#M1101355</link>
      <description>&lt;P&gt;You can create a custom cipher list (as per the example above) and use that.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 08:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851087#M1101355</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-06-08T08:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851089#M1101356</link>
      <description>&lt;P&gt;Check below&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 15:58:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851089#M1101356</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-08T15:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851301#M1101362</link>
      <description>&lt;P&gt;I have defined SSL Cipher -&amp;gt; Selected&amp;nbsp;&lt;SPAN&gt;DTLSv1.2, TLSv1.2&lt;/SPAN&gt;&amp;nbsp;&amp;amp; selected it under SSL settings. Performed a VA scan from nessus still the vulnerability of TLS 1.1 is shown. Please advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show running-config all ssl&lt;BR /&gt;ssl server-version tlsv1.2 dtlsv1.2&lt;BR /&gt;ssl client-version tlsv1&lt;BR /&gt;ssl cipher default medium&lt;BR /&gt;ssl cipher tlsv1 medium&lt;BR /&gt;ssl cipher tlsv1.1 medium&lt;BR /&gt;ssl cipher tlsv1.2 medium&lt;BR /&gt;ssl cipher dtlsv1 medium&lt;BR /&gt;ssl cipher dtlsv1.2 medium&lt;BR /&gt;ssl dh-group group14&lt;BR /&gt;ssl ecdh-group group19&lt;BR /&gt;ssl certificate-authentication fca-timeout 2&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 11:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851301#M1101362</guid>
      <dc:creator>taro75</dc:creator>
      <dc:date>2023-06-08T11:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851306#M1101363</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Check below&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 15:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851306#M1101363</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-08T15:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851314#M1101364</link>
      <description>&lt;P&gt;I am using FDM not FMC. I cannot edit the default, so defined as shown below and selected the same under SSL Settings. Still there is no luck 1.1 is still enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="taro75_0-1686222781225.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186827iD9152C5556DB9D54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="taro75_0-1686222781225.png" alt="taro75_0-1686222781225.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 11:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851314#M1101364</guid>
      <dc:creator>taro75</dc:creator>
      <dc:date>2023-06-08T11:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851324#M1101365</link>
      <description>&lt;P&gt;Check below&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 16:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851324#M1101365</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-08T16:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851435#M1101375</link>
      <description>&lt;P&gt;Are you scanning the management IP or an interface with SSL VPN setup? As noted in &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt; 's post, the SSL settings only apply to SSL VPN.&lt;/P&gt;
&lt;P&gt;Changing the SSL settings for the management interface is not supported by Cisco. It can be done with a "hack" from the expert mode cli, but it's not anything Cisco endorses.&lt;/P&gt;
&lt;P&gt;See this post and the linked post in it: &lt;A href="https://community.cisco.com/t5/vpn/how-to-disable-tls-v1-0-v1-1-on-ftd-using-the-fdm-or-cli/m-p/4843044#M289359" target="_blank"&gt;https://community.cisco.com/t5/vpn/how-to-disable-tls-v1-0-v1-1-on-ftd-using-the-fdm-or-cli/m-p/4843044#M289359&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 16:03:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851435#M1101375</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-06-08T16:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: TLS Version 1.1 Protocol Deprecated</title>
      <link>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851494#M1101380</link>
      <description>&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs23509" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs23509&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This bug and ver. 7.0 fixed it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 15:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-version-1-1-protocol-deprecated/m-p/4851494#M1101380</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-08T15:58:23Z</dc:date>
    </item>
  </channel>
</rss>

