<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cipher Related Issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911645#M1103797</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Thank you, Rob; your assistance was really appreciated. But I have a few more questions. If ciphers are deprecated in a newer version and we are utilizing that cipher in our present setup, we must modify it before patching. How to choose the appropriate security cipher to use for Firewalls in order to replace the previous deprecated one.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;For Example:&amp;nbsp;&lt;STRONG&gt;Model:&lt;/STRONG&gt; Cisco ASA 5525x&lt;BR /&gt;&lt;STRONG&gt;Current Version:&lt;/STRONG&gt; 9.8(4)29&lt;BR /&gt;&lt;STRONG&gt;Recommended Version:&lt;/STRONG&gt; 9.16(4)14&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1 will change to &lt;I&gt;ssh key&lt;/I&gt;-exchange &lt;I&gt;group group14&lt;/I&gt;-&lt;I&gt;sha1 &lt;/I&gt;automatically by updating to version 9.16.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2023 21:33:30 GMT</pubDate>
    <dc:creator>edwinjosey</dc:creator>
    <dc:date>2023-08-24T21:33:30Z</dc:date>
    <item>
      <title>Cipher Related Issues</title>
      <link>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911493#M1103787</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is my first post on this forum. Actually, I'm having trouble upgrading to the latest Cisco firmware in a site-to-site VPN.&lt;BR /&gt;The ciphers used in the current version do not work in the upgraded version, so I want to know which ciphers will work and which will be deprecated or eliminated in the newer version before patching it to the new version. Otherwise, the vpn tunnel will go down after patching, so please direct me to where I can find all the details about this.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 17:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911493#M1103787</guid>
      <dc:creator>edwinjosey</dc:creator>
      <dc:date>2023-08-24T17:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher Related Issues</title>
      <link>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911499#M1103788</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1579345"&gt;@edwinjosey&lt;/a&gt; the weak ciphers were depreciated from 9.13 and removed in subsequent releases and are detailed in the release notes &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/release/notes/asarn913.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/release/notes/asarn913.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1692898042464.png" style="width: 778px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195222iFC7DA277BB2A8DCA/image-dimensions/778x422?v=v2" width="778" height="422" role="button" title="RobIngram_0-1692898042464.png" alt="RobIngram_0-1692898042464.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 17:28:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911499#M1103788</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-24T17:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher Related Issues</title>
      <link>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911645#M1103797</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Thank you, Rob; your assistance was really appreciated. But I have a few more questions. If ciphers are deprecated in a newer version and we are utilizing that cipher in our present setup, we must modify it before patching. How to choose the appropriate security cipher to use for Firewalls in order to replace the previous deprecated one.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;For Example:&amp;nbsp;&lt;STRONG&gt;Model:&lt;/STRONG&gt; Cisco ASA 5525x&lt;BR /&gt;&lt;STRONG&gt;Current Version:&lt;/STRONG&gt; 9.8(4)29&lt;BR /&gt;&lt;STRONG&gt;Recommended Version:&lt;/STRONG&gt; 9.16(4)14&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1 will change to &lt;I&gt;ssh key&lt;/I&gt;-exchange &lt;I&gt;group group14&lt;/I&gt;-&lt;I&gt;sha1 &lt;/I&gt;automatically by updating to version 9.16.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 21:33:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911645#M1103797</guid>
      <dc:creator>edwinjosey</dc:creator>
      <dc:date>2023-08-24T21:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher Related Issues</title>
      <link>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911821#M1103813</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1579345"&gt;@edwinjosey&lt;/a&gt; in regard to VPN ciphers, you should be fine using AES (GCM or CBC), SHA (2 preferred), DH group 19, 20 or 21. You should change the VPN configuration before migration to avoid post upgrade issues.&lt;/P&gt;
&lt;P&gt;Cisco Next Generation Encryption recommendations - &lt;A href="https://sec.cloudapps.cisco.com/security/center/resources/next_generation_cryptography" target="_blank"&gt;https://sec.cloudapps.cisco.com/security/center/resources/next_generation_cryptography&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 07:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4911821#M1103813</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-25T07:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher Related Issues</title>
      <link>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4915580#M1103924</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;Dear Rob,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Thank you for your help. But in my scenario some of the deprecated ciphers are not mentioned in your link. so leaving you with my current details of my firewall.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto map outside_map0 3 set pfs group5 at line 2258&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group5&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto map outside_map0 3 set pfs group5 at line 2258&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: set pfs group5&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev2 policy 2 at line 2316&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Matc&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;h With: crypto ikev2 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 5 at line 2319&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 5&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 10 at line 2324&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2328&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 20 at line 2330&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2334&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 40 at line 2336&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2340&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 50 at line 2342&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2346&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 70 at line 2348&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2352&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 80 at line 2354&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2358&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 100 at line 2360&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: encryption 3des at line 2362&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: encryption 3des&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2364&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 110 at line 2366&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: encryption 3des at line 2368&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: encryption 3des&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2370&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 130 at line 2372&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: encryption des at line 2374&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: encryption des&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2376&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: crypto ikev1 policy 140 at line 2378&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: crypto ikev1 policy&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: encryption des at line 2380&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: encryption des&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: group 2 at line 2382&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match With: group 2&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;Match Found: ssh key-exchange group dh-group1-sha1 at line 2399&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#f5f5f5"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;&lt;FONT color="#000000"&gt;Match With: ssh key-exchange group dh-group1-sha1&lt;/FONT&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#f5f5f5"&gt;&lt;FONT face="Lucida Console, serif"&gt;&lt;FONT size="2"&gt;&lt;FONT color="#000000"&gt;All the above mentioned ciphers are going to deprecated when it is upgraded to the recommended version which is given below and&amp;nbsp;I have to&amp;nbsp;&lt;SPAN&gt;find out what, either the best security cipher to use for the one being removed, or find an alternative command to be used for the one being removed.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Model: Cisco ASAv10&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Current Version: 9.8(4)29&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Recommended Version: 9.16(3)19&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 16:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4915580#M1103924</guid>
      <dc:creator>edwinjosey</dc:creator>
      <dc:date>2023-08-31T16:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cipher Related Issues</title>
      <link>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4915582#M1103925</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1579345"&gt;@edwinjosey&lt;/a&gt; you can find the supported crypto ciphers for ASA 9.16 - &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/configuration/vpn/asa-916-vpn-config/vpn-ike.html#ID-2441-00000116" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/configuration/vpn/asa-916-vpn-config/vpn-ike.html#ID-2441-00000116&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can replace your DH group 2/5 with 14, 15, 16, 19, 20 or 21 and replace DES/3DES with AES (128 or 256) which is supported with 9.16.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 16:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cipher-related-issues/m-p/4915582#M1103925</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-31T16:16:13Z</dc:date>
    </item>
  </channel>
</rss>

