cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
888
Views
0
Helpful
0
Replies

SSH Server CBC Mode Ciphers & SSH Weak MAC Vulnerabilities Firesight

Colin Higgins
Level 2
Level 2

I have a Firesight Management Server (2000) that manages various Firepower devices on my network. They are running the latest software versions.

My security auditor keeps flagging both the management server and the sensors for:

SSH Weak Algorithms enabled (MD5 & 96bit)

SSL 64bit block size ciphers (SWEET32 attack)

Is there any way to correct this through disabling certain ciphers, making modifications, etc.?

I do NOT want to lock myself out of my IPS system or damage the software.

thanks

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card