cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7727
Views
0
Helpful
4
Replies

DTLS 1.0 vs TLS 1.0 vulnerability

fsebera
Level 4
Level 4

We run the latest version of the AnyConnect client and notice

SSL tunnel uses TLS 1.2 encapsulation

DTLS tunnel uses DTLS 1.0 encapsulation.

Research shows TLS 1.0 is not PCI complaint; where does DTLS 1.0 fit in here?

Is there a way or need to migrate from DTLS 1.0 to DTLS 1.2?

Thank you

Frank 

1 Accepted Solution

Accepted Solutions

DTLS 1.0 is comparable to TLS1.1, not TLS1.0. Although DTLS 1.2 is standardized for quite some time, it's not implemented in the ASA (as of version 9.7).

View solution in original post

4 Replies 4

DTLS 1.0 is comparable to TLS1.1, not TLS1.0. Although DTLS 1.2 is standardized for quite some time, it's not implemented in the ASA (as of version 9.7).

Hi Karsten,

Yes I just did see a document stating DTLS 1.0 is based on TLS 1.1 standard and thus DTLS 1.0 appears to be fine. Thank you for confirming though!

I guess we will look forward to the AnyConnect client update sometime in the future.

Thanks

Frank

Cisco has enabled TLS v1.2 support for DTLS based VPN connection with the AOS 9.10 code trail. To establish DTLS based VPN connections using TLS v1.2  you need to use the Cisco AnyConnect 4.7 client which is not (yet) officially released but available as alpha (or beta) version.

 

robertokippins
Level 1
Level 1

Hi What's the most secure setting to use here:

 

Capture.PNG