04-20-2022 05:03 AM - edited 05-02-2022 03:30 AM
04-20-2022 05:19 AM - edited 04-20-2022 05:21 AM
@mze here...https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn63389
https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html
DTLS 1.2, as defined in RFC- 6347, is now supported for AnyConnect remote access in addition to the currently supported DTLS 1.0 (1.1 version number is not used for DTLS.) This applies to all ASA models except the 5506-X, 5508-X, and 5516-X; and applies when the ASA is acting as a server only, not a client. DTLS 1.2 supports additional ciphers, as well as all current TLS/DTLS cyphers, and a larger cookie size.
04-20-2022 05:12 AM
@mze unfortunately you cannot enable DTLS 1.2 on those older ASA (5506-X, 5508-X, and 5516-X).
Alternatively you could run IKEv2/IPSec which would get you comparable performance to DTLS1.2 or upgrade the hardware.
04-20-2022 05:14 AM
thanks Rob for quick response is there cisco docuemntation which i can refer for validation
04-20-2022 05:19 AM - edited 04-20-2022 05:21 AM
@mze here...https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn63389
https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html
DTLS 1.2, as defined in RFC- 6347, is now supported for AnyConnect remote access in addition to the currently supported DTLS 1.0 (1.1 version number is not used for DTLS.) This applies to all ASA models except the 5506-X, 5508-X, and 5516-X; and applies when the ASA is acting as a server only, not a client. DTLS 1.2 supports additional ciphers, as well as all current TLS/DTLS cyphers, and a larger cookie size.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide