cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
330
Views
0
Helpful
2
Replies

Cisco Firepower TLS decryption cipher list

tunolno1
Level 1
Level 1

Any active Firepower users - can you point me towards a list of cipher supprted for SSL decryption?

I can't find anything in the docs except stupid note that you have to ask TAC for it...

 

2 Replies 2

marce1000
VIP
VIP

 

      % nmap -sV --script ssl-enum-ciphers -p 443   your-firepower-hostname 
      The above example tests on port 443 , usually uses for https , if there is another port using ssl and you
      want to test , then change the port number accordingly

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

ccieexpert
Spotlight
Spotlight

nmap to the firepower ip will not help determine decryption ciphers..

NMAP through the box to a few major websites will reveal the ciphers that it is supporting..

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/decryption-rules.html#id_80972

ccieexpert_0-1721442489622.png

 

 

ccieexpert_1-1721442598272.png

*** Please mark as helpful if this was useful ***

 

Review Cisco Networking for a $25 gift card