cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
1003
Views
0
Helpful
0
Replies

SSH Server CBC Mode Ciphers & SSH Weak MAC Vulnerabilities Firesight

Colin Higgins
Level 2
Level 2

I have a Firesight Management Server (2000) that manages various Firepower devices on my network. They are running the latest software versions.

My security auditor keeps flagging both the management server and the sensors for:

SSH Weak Algorithms enabled (MD5 & 96bit)

SSL 64bit block size ciphers (SWEET32 attack)

Is there any way to correct this through disabling certain ciphers, making modifications, etc.?

I do NOT want to lock myself out of my IPS system or damage the software.

thanks

0 Replies 0
Review Cisco Networking for a $25 gift card