<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic This Cisco posting re Next in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-server-cbc-mode-ciphers-enabled-and-ssh-weak-mac-algorithms/m-p/2620857#M920243</link>
    <description>&lt;P&gt;&lt;A href="http://www.cisco.com/web/about/security/intelligence/nextgen_crypto.html"&gt;This Cisco posting re Next Generation Encryption&lt;/A&gt; lists several ways to accomplish what's being asked.&lt;/P&gt;&lt;P&gt;Take care that you don't effectively perform a denial of service on yourself. Depending on how (or if) you are currently using them, the weaker algorithms may be required to support remote clients or peers on external VPNs.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2015 18:09:29 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-04-21T18:09:29Z</dc:date>
    <item>
      <title>SSH Server CBC Mode Ciphers Enabled and SSH Weak MAC Algorithms Enabled</title>
      <link>https://community.cisco.com/t5/network-security/ssh-server-cbc-mode-ciphers-enabled-and-ssh-weak-mac-algorithms/m-p/2620856#M920242</link>
      <description>&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;As per VAPT audit carried out in my client side they ask to make changes in following points in 2960 switch and 3825,3845, 3945 and 7609 routers kindly provide the correct solution. as per my search till now it is not highly required but how can i answer and convince this to my client.&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;FONT color="#1F497D"&gt;&lt;SPAN lang="en-IN"&gt;Obser 1- “&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color="black"&gt;SSH Server CBC Mode Ciphers Enabled” :&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;FONT color="black"&gt;&lt;B&gt;Kindly suggest the command to implement CTR or GCM ciphers and to disable CBC Mode Ciphers.&amp;nbsp; &amp;nbsp;The CISCO documents do not have any information for implementation of CTR or GCM in CISCO devices.&lt;/B&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;FONT color="black"&gt;&lt;SPAN lang="en-IN"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;FONT color="black"&gt;Obser 2 – “SSH Weak MAC Algorithms Enabled “&amp;nbsp; :&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;FONT color="black"&gt;&lt;SPAN lang="en-IN"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV style="color: rgb(0, 0, 0); font-family: 'Segoe UI', Helvetica, Arial, sans-serif; font-size: medium; line-height: normal; margin: 0px;"&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;FONT color="black"&gt;&lt;B&gt;Kindly suggest the command to disable SSH Weak MAC Algorithms in CISCO devices.&lt;/B&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-server-cbc-mode-ciphers-enabled-and-ssh-weak-mac-algorithms/m-p/2620856#M920242</guid>
      <dc:creator>patilranjitv</dc:creator>
      <dc:date>2020-02-21T13:27:22Z</dc:date>
    </item>
    <item>
      <title>This Cisco posting re Next</title>
      <link>https://community.cisco.com/t5/network-security/ssh-server-cbc-mode-ciphers-enabled-and-ssh-weak-mac-algorithms/m-p/2620857#M920243</link>
      <description>&lt;P&gt;&lt;A href="http://www.cisco.com/web/about/security/intelligence/nextgen_crypto.html"&gt;This Cisco posting re Next Generation Encryption&lt;/A&gt; lists several ways to accomplish what's being asked.&lt;/P&gt;&lt;P&gt;Take care that you don't effectively perform a denial of service on yourself. Depending on how (or if) you are currently using them, the weaker algorithms may be required to support remote clients or peers on external VPNs.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 18:09:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-server-cbc-mode-ciphers-enabled-and-ssh-weak-mac-algorithms/m-p/2620857#M920243</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-04-21T18:09:29Z</dc:date>
    </item>
  </channel>
</rss>

