<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: That is wrong. See Wireshark capture of Client Hello from... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/3376065#M174819</link>
    <description>&lt;P&gt;Hi Paolo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What release version of 3.1 are you running for that trace, as I get similar results to the others above, in that it stops working when client set to TLS1.1 so I wondered if a certain versions of 3.1 worked whilst others didn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I notice now that all anyconnect 3.1 release notes, software downloads are now gone from cisco.com&lt;/P&gt;</description>
    <pubDate>Tue, 01 May 2018 15:55:44 GMT</pubDate>
    <dc:creator>Merlin-Cisco</dc:creator>
    <dc:date>2018-05-01T15:55:44Z</dc:date>
    <item>
      <title>TLS v1.1 vs AnyConnect client v3.x</title>
      <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782985#M174814</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm attempting to get an ASA to PCI compliance so TLS v1.0 cannot be used.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When I disable TLS v1.0 and enable TLS v1.1, AnyConnect v3.x clients cannot connect&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;AnyConnect v4.x clients (which require a preimum license) can connect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there a solution without having to upgrade to an AnyConnect Premium license?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782985#M174814</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2019-03-12T06:54:15Z</dc:date>
    </item>
    <item>
      <title>It's not a premium license</title>
      <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782986#M174815</link>
      <description>&lt;P&gt;It's not a premium license that you need. For AnyConnect 4 you "only" need the AnyConnect Plus license which is not&amp;nbsp;as expensive as the older premium licenses were. &lt;A href="http://www.cisco.com/c/dam/en/us/products/security/anyconnect-og.pdf"&gt;More&amp;nbsp;details in the AC ordering guide&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2015 18:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782986#M174815</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-11-17T18:17:34Z</dc:date>
    </item>
    <item>
      <title>Hi Larry,</title>
      <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782987#M174816</link>
      <description>&lt;P&gt;Hi Larry,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLS v1.1 is not supported by the Anyconnect client v3.x . For you will have role back to TLS v1.0.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman',serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman',serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman',serif;"&gt;Gurjot Singh&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman',serif;"&gt;Cisco TAC&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 05:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782987#M174816</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2015-11-18T05:10:54Z</dc:date>
    </item>
    <item>
      <title>Thanks for the link.</title>
      <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782988#M174817</link>
      <description>&lt;P&gt;Thanks for the link.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 05:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/2782988#M174817</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2015-11-18T05:11:21Z</dc:date>
    </item>
    <item>
      <title>That is wrong. See Wireshark capture of Client Hello from...</title>
      <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/3350254#M174818</link>
      <description>&lt;P&gt;That is wrong. See Wireshark capture of Client Hello from AnyConnect 3.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLSv1.1 Record Layer: Handshake Protocol: Client Hello&lt;BR /&gt; Content Type: Handshake (22)&lt;BR /&gt; &lt;STRONG&gt;Version: TLS 1.1 (0x0302)&lt;/STRONG&gt;&lt;BR /&gt; Length: 99&lt;BR /&gt; Handshake Protocol: Client Hello&lt;BR /&gt; Handshake Type: Client Hello (1)&lt;BR /&gt; Length: 95&lt;BR /&gt; Version: TLS 1.1 (0x0302)&lt;BR /&gt; Random: 5aad3dc8639ca8ea4944bc71e363602801a4106d5621fe67...&lt;BR /&gt; Session ID Length: 0&lt;BR /&gt; Cipher Suites Length: 14&lt;BR /&gt; Cipher Suites (7 suites)&lt;BR /&gt; Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a)&lt;BR /&gt; Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (0xc009)&lt;BR /&gt; Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)&lt;BR /&gt; Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)&lt;BR /&gt; Cipher Suite: TLS_RSA_WITH_AES_256_CBC_SHA (0x0035)&lt;BR /&gt; Cipher Suite: TLS_RSA_WITH_AES_128_CBC_SHA (0x002f)&lt;BR /&gt; Cipher Suite: TLS_RSA_WITH_3DES_EDE_CBC_SHA (0x000a)&lt;BR /&gt; Compression Methods Length: 1&lt;BR /&gt; Compression Methods (1 method)&lt;BR /&gt; Extensions Length: 40&lt;BR /&gt; Extension: status_request (len=5)&lt;BR /&gt; Extension: supported_groups (len=8)&lt;BR /&gt; Extension: ec_point_formats (len=2)&lt;BR /&gt; Extension: SessionTicket TLS (len=0)&lt;BR /&gt; Extension: extended_master_secret (len=0)&lt;BR /&gt; Extension: renegotiation_info (len=1)&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 16:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/3350254#M174818</guid>
      <dc:creator>paolo bevilacqua</dc:creator>
      <dc:date>2018-03-17T16:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: That is wrong. See Wireshark capture of Client Hello from...</title>
      <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/3376065#M174819</link>
      <description>&lt;P&gt;Hi Paolo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What release version of 3.1 are you running for that trace, as I get similar results to the others above, in that it stops working when client set to TLS1.1 so I wondered if a certain versions of 3.1 worked whilst others didn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I notice now that all anyconnect 3.1 release notes, software downloads are now gone from cisco.com&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 15:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/3376065#M174819</guid>
      <dc:creator>Merlin-Cisco</dc:creator>
      <dc:date>2018-05-01T15:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: That is wrong. See Wireshark capture of Client Hello from...</title>
      <link>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/3376068#M174820</link>
      <description>&lt;P&gt;&lt;EM&gt;What release version of 3.1 are you running for that trace, as I get similar results to the others above, in that it stops working when client set to TLS1.1 so I wondered if a certain versions of 3.1 worked whilst others didn't.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No. AnyConnect, any version, do&amp;nbsp;adapt to the Windows version running. Newest OS versions prevent obsolete TLS versions to be negotiated.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 16:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-v1-1-vs-anyconnect-client-v3-x/m-p/3376068#M174820</guid>
      <dc:creator>paolo bevilacqua</dc:creator>
      <dc:date>2018-05-01T16:08:10Z</dc:date>
    </item>
  </channel>
</rss>

