<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic inquiries for WLC 3504 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971500#M263877</link>
    <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;i have some inquiries for WLC 3504&lt;/P&gt;&lt;P&gt;- how can i get current TLS version applied on WLC ?&lt;/P&gt;&lt;P&gt;- how can i get current SSL version applied on WLC ?&lt;/P&gt;&lt;P&gt;- what is recommended version for SSL now and TLS ?&lt;/P&gt;&lt;P&gt;- when i access WLC GUI i need to install certificate ( self sign ) how can i install it from CA?&lt;/P&gt;&lt;P&gt;- after apply new TLS and SSL versions, it mean old versions is off ? or i have to disable them manually ?&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 08:51:45 GMT</pubDate>
    <dc:creator>Ahmed Tarek</dc:creator>
    <dc:date>2023-12-05T08:51:45Z</dc:date>
    <item>
      <title>inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971500#M263877</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;i have some inquiries for WLC 3504&lt;/P&gt;&lt;P&gt;- how can i get current TLS version applied on WLC ?&lt;/P&gt;&lt;P&gt;- how can i get current SSL version applied on WLC ?&lt;/P&gt;&lt;P&gt;- what is recommended version for SSL now and TLS ?&lt;/P&gt;&lt;P&gt;- when i access WLC GUI i need to install certificate ( self sign ) how can i install it from CA?&lt;/P&gt;&lt;P&gt;- after apply new TLS and SSL versions, it mean old versions is off ? or i have to disable them manually ?&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 08:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971500#M263877</guid>
      <dc:creator>Ahmed Tarek</dc:creator>
      <dc:date>2023-12-05T08:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971502#M263878</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI : %&amp;nbsp; &amp;nbsp;nmap --script ssh2-enum-algos&amp;nbsp; controller-hostname&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;% &amp;nbsp;nmap --script ssl-enum-ciphers -p 443 controller-hostname&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; In general , if you are worried about security issues concerning TLS/SSL then upgrade the controller according to :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; and review the situation again ,&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 08:56:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971502#M263878</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-12-05T08:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971510#M263881</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what are these&lt;/P&gt;&lt;P&gt;% nmap --script ssh2-enum-algos controller-hostname&lt;BR /&gt;% nmap --script ssl-enum-ciphers -p 443 controller-hostname&lt;/P&gt;&lt;P&gt;are they command i need to type in CLI ?&lt;/P&gt;&lt;P&gt;sorry but i need to understand&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 09:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971510#M263881</guid>
      <dc:creator>Ahmed Tarek</dc:creator>
      <dc:date>2023-12-05T09:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971552#M263886</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- nmap is hacking tool ; you can download it from&amp;nbsp;&lt;A href="https://nmap.org/" target="_blank"&gt;https://nmap.org/&lt;/A&gt;&amp;nbsp; &amp;nbsp; but for your purposes you can consider yourself being an ethical hacker ! (You can install nmap on a windows on linux host ; the commands must then be executed from where nmap was installed)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 10:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4971552#M263886</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-12-05T10:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4972597#M263954</link>
      <description>&lt;P&gt;- Upgrade software to 8.10.190.0 (or later as per TAC recommended link below)&lt;/P&gt;
&lt;P&gt;- Ensure WLC is configured for maximum security options as per the config guide:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/administration_of_cisco_wlc.html#ID520" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/administration_of_cisco_wlc.html#ID520&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/administration_of_cisco_wlc.html#hsts_policy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/administration_of_cisco_wlc.html#hsts_policy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Update the certificate as per the guides:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/managing_certificates.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/managing_certificates.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/215425-troubleshoot-certificate-installation-on.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/215425-troubleshoot-certificate-installation-on.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 18:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4972597#M263954</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-12-06T18:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4972961#M263968</link>
      <description>&lt;P&gt;thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt; for your links,&lt;/P&gt;&lt;P&gt;but is there any command i can check current TLS version from CLI or GUI for WLC 3504 ?&lt;/P&gt;&lt;P&gt;all commands i found related to other WLCs&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 07:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4972961#M263968</guid>
      <dc:creator>Ahmed Tarek</dc:creator>
      <dc:date>2023-12-07T07:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973185#M263973</link>
      <description>&lt;P&gt;Not specifically - refer to Marce's answer for how to check that.&lt;/P&gt;
&lt;P&gt;On the WLC you can use:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;grep include "Secure Web" "show network summary"&lt;/FONT&gt;&lt;BR /&gt;to check the configured settings but that won't show you TLS versions explicitly.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 12:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973185#M263973</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-12-07T12:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973230#M263975</link>
      <description>&lt;P&gt;thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;show network summary show the following&lt;/P&gt;&lt;P&gt;Secure Web Mode............................. Enable&lt;/P&gt;&lt;P&gt;it mean what ? which TLS version is applied ? 1.1 or 1.2 or 1.3 ?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 12:16:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973230#M263975</guid>
      <dc:creator>Ahmed Tarek</dc:creator>
      <dc:date>2023-12-07T12:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973245#M263976</link>
      <description>&lt;P&gt;As I already explained it does &lt;STRONG&gt;not&lt;/STRONG&gt; tell you the TLS version(s).&amp;nbsp; &lt;BR /&gt;&lt;FONT size="6" color="#FF0000"&gt;Refer to Marce's earlier answer for how to check TLS versions!&lt;/FONT&gt;&lt;BR /&gt;That line just tells you that https is enabled.&lt;BR /&gt;The lines you're more interested in are "Secure Web Mode Cipher-Option High" which should be Enable and "Secure Web Mode SSL Protocol" which should be Disable.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 12:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973245#M263976</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-12-07T12:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973374#M263977</link>
      <description>&lt;P&gt;&lt;STRONG&gt;i can not use his commands, is not allowed to use this in my environment.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;i hope now you can get what i mean&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 13:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973374#M263977</guid>
      <dc:creator>Ahmed Tarek</dc:creator>
      <dc:date>2023-12-07T13:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: inquiries for WLC 3504</title>
      <link>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973412#M263978</link>
      <description>&lt;P&gt;Then it is impossible to do what you want.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 13:46:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/inquiries-for-wlc-3504/m-p/4973412#M263978</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-12-07T13:46:26Z</dc:date>
    </item>
  </channel>
</rss>

