03-22-2023 01:08 AM - edited 03-22-2023 01:11 AM
Hi all,
We purchased the Firepower 2110 loaded with ASA. While sending from factory and there was no base license enabled.
We commissioned the Firewall and while we are trying to access the Firewall from outside Network it throws an error as SSL.
03-22-2023 01:58 AM
@qautomation the error indicates a TLS cipher mismatch.
What is configured on the ASA? Run the command show ssl
You can configure secure TLS/SSL protocol, from the CLI enter the command ssl server-version tlsv1.2 dtlsv1.2
Then to use the more secure ciphers, from the CLI enter the commands:
ssl cipher tlsv1.2 high
ssl cipher dtlsv1.2 high
More information here on configuring secure TLS ciphers on the ASA - https://integratingit.wordpress.com/2021/01/27/securing-asa-tls-ciphers/
If you still have a problem please provide your configuration so we can review.
03-22-2023 05:42 AM
Did you register the ASA with a Smart license token yet? You will need to do so and make sure that the "allow export controlled features" tick box is checked in your smart portal when creating the registration token. That will ensure that 3DES-AES licensing is enabled which allows the ASA to activate modern cryptographic protocol support.
03-22-2023 05:46 AM
Hi,
We hadn't registered the smart license token yet. We would like to understand whether due to this we are not able to access it from Outside Network. As the Firewalls installed in Air-Gapped(On-Perm). During Purchase of the Firewall we have to request for PLR ?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: