<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Firewall Threat Defense V7 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939909#M1105019</link>
    <description>&lt;P&gt;I had another customer's peer claim this as well. Often they are Just Wrong. ASA has supported IKEv2 with DH Group 14 since version 9.0 which is available even on the log-past-end-of-life ASA 5500 series (5505/5510/5520/5540/5550/5585).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/td-p/3010274" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/td-p/3010274&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2023 13:36:27 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2023-10-13T13:36:27Z</dc:date>
    <item>
      <title>Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939860#M1105008</link>
      <description>&lt;P&gt;Hi guys,&lt;BR /&gt;I am asking you for help in activating my DH group 5&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhgroup.PNG" style="width: 207px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/199620i0FEF35591BEF9156/image-size/large?v=v2&amp;amp;px=999" role="button" title="dhgroup.PNG" alt="dhgroup.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939860#M1105008</guid>
      <dc:creator>Diallo</dc:creator>
      <dc:date>2023-10-13T12:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939872#M1105011</link>
      <description>&lt;P&gt;its been deprecated 6.7 onwards :&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;&lt;CAPTION&gt;&lt;SPAN class="table--title-label tabletitle"&gt;Table 2. &lt;/SPAN&gt;&lt;SPAN class="tabletitle"&gt;Version 6.7.0 Deprecated Features&lt;/SPAN&gt;&lt;/CAPTION&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html#id_110361" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html#id_110361&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939872#M1105011</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-10-13T12:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939873#M1105012</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Its been flagged as&lt;U&gt; &lt;FONT color="#FF6600"&gt;depreciated&amp;nbsp;&lt;/FONT&gt;&lt;/U&gt; ,&lt;EM&gt; hence can no longer be activated ,&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939873#M1105012</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-10-13T12:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939875#M1105013</link>
      <description>&lt;P&gt;So there is no way to activate it???&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939875#M1105013</guid>
      <dc:creator>Diallo</dc:creator>
      <dc:date>2023-10-13T12:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939876#M1105014</link>
      <description>&lt;P&gt;So also there is no other possibility of using version 1 or 2&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939876#M1105014</guid>
      <dc:creator>Diallo</dc:creator>
      <dc:date>2023-10-13T12:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939880#M1105016</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/831623"&gt;@Diallo&lt;/a&gt; even on 7.3 you can still select DH group 5 to use in an IKEv2 policy. Although I would strongly recommend not doing so, as it's likely this will shortly be removed from FTD altogether (it has already been removed from ASA). I recommend you reconfigure the peer configuration to use a stronger DH group&amp;nbsp; (19,20 or 21 etc).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1697201780367.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/199622i67B5B7D8E34D5E5B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobIngram_0-1697201780367.png" alt="RobIngram_0-1697201780367.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939880#M1105016</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-10-13T12:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939895#M1105017</link>
      <description>&lt;P&gt;I just have to use it in the creation of a VPN with a partner who uses ASA and tells me that he only uses versions 1,2 and 5.&lt;/P&gt;&lt;P&gt;With its status there can it work???&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 13:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939895#M1105017</guid>
      <dc:creator>Diallo</dc:creator>
      <dc:date>2023-10-13T13:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939899#M1105018</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/831623"&gt;@Diallo&lt;/a&gt; yes, but if you use DH group 5 (whilst it's still available to deploy) you will not be able to upgrade your FTD in future, as I already stated the weaker ciphers (including DH group 5) will be removed in upcoming releases. I would suggest the partner upgrades their software to support stronger crypto, the DH groups their software supports is weak and insecure.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 13:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939899#M1105018</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-10-13T13:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939909#M1105019</link>
      <description>&lt;P&gt;I had another customer's peer claim this as well. Often they are Just Wrong. ASA has supported IKEv2 with DH Group 14 since version 9.0 which is available even on the log-past-end-of-life ASA 5500 series (5505/5510/5520/5540/5550/5585).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/td-p/3010274" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/td-p/3010274&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 13:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939909#M1105019</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-10-13T13:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939912#M1105020</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;thank you very much for your suggestions.&lt;BR /&gt;You are absolutely right, I will talk to the partner about updating their ASA if possible.&lt;/P&gt;&lt;P&gt;But in the meantime we are going to use group 5 there with its status like that.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 13:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939912#M1105020</guid>
      <dc:creator>Diallo</dc:creator>
      <dc:date>2023-10-13T13:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall Threat Defense V7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939919#M1105021</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;thank you very much for your solution I see that this is possible with ASA5520 for group 14&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 13:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-threat-defense-v7/m-p/4939919#M1105021</guid>
      <dc:creator>Diallo</dc:creator>
      <dc:date>2023-10-13T13:53:07Z</dc:date>
    </item>
  </channel>
</rss>

