03-13-2023 07:55 AM - edited 03-13-2023 07:57 AM
Hi Team,
Default, SDWAN devices use DTLS to encryt packet (vedge, vmanage, vmart, vbond). So if I use DTLS, TLS can be disabled or TLS still available ? And i wonder that are there any way to disable TLS if i want ?
Thank you in advance !
Solved! Go to Solution.
03-13-2023 01:06 PM
Hi,
the reason is, vSmart can be configured for TLS, then between vSmart and vManage security protocol will be TLS (even though DTLS is configured on vManage). Thus, vManage needs to open respective ports in daemon.
I don't see any option to disable (totally) TLS or DTLS at OS level. If yuo have security concerns, block those ports on firewall level.
Below is ports used by SD-WAN elements:
03-13-2023 08:12 AM - edited 03-13-2023 08:16 AM
Hi,
control connection to vBond (from vSmart/vManage/cEdge) is always DTLS based. vBond does not support TLS.
Based on configuration of vSmart and vManage, control connection from cEdge to them and between each other can be DTLS or TLS. In configuration it is either DTLS or TLS, there is no "both" option. But if one device is DTLS other device is TLS, then TLS is chosen between them.
This section of CVD describes in detail:
To disable TLS, just configure all vSmart and vManage to use DTLS under security configuration (template or CLI).
03-13-2023 08:32 AM
Hi @Kanan Huseynli ,
Default vSmart and vManage use DTLS, if I dont change DTLS to TLS, they will use DTLS and TLS is disabled, is it right ?
If its right, when I show port open in vmanage, TLS is still open ? I am confuse ....
03-13-2023 01:06 PM
Hi,
the reason is, vSmart can be configured for TLS, then between vSmart and vManage security protocol will be TLS (even though DTLS is configured on vManage). Thus, vManage needs to open respective ports in daemon.
I don't see any option to disable (totally) TLS or DTLS at OS level. If yuo have security concerns, block those ports on firewall level.
Below is ports used by SD-WAN elements:
03-13-2023 07:42 PM
@Kanan Huseynli Thank you so much ! I am appreciate it !
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide