cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1463
Views
0
Helpful
1
Replies

TLS Legacy Connections

JonDutton5674
Level 1
Level 1

We are trying to find a way to identify any inbound/outbound connections via TLS v1 and TLS v1.1. I know the content is available within the logs but is there a way to flag or generate a report so we can start working with our clients to transition them away to TLS v1.2.

1 Reply 1

Libin Varghese
Cisco Employee
Cisco Employee

Currently logs are the only way to review this information and there are no default reports for it.

 

Async OS 13 and above for ESA allow for consolidated event logs in CEF format supported by most common SIEM solutions.

Fields available for that log type include TLS incoming protocol and TLS outgoing protocol.

 

You could try configuring that with other fields of your choice and use a SIEM solution to generate reports based off those logs.

 

https://docs.ces.cisco.com/docs/single-log-line-sll

 

Regards,

Libin