cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
656
Views
0
Helpful
1
Replies

How can I configure AnyConnect to use TLSv1 instead of SSLv3

murraymwps
Level 1
Level 1

We are running AnyConnect 3.1.06073 and have had to shut down SSLv3 on the firewall for PCI compliance:

 

ssl server-version tlsv1-only

 

 But now some AnyConnect users are unable to connect. When I set the ASA to accept SSLv3 too:

 

ssl server-version any

 

All users are able to connect. The clients are the same version. How can I configure the client to connect via TLSv1 instead of SSLv3?

 

Thanks,

-mike

1 Reply 1

Kanwaljeet Singh
Cisco Employee
Cisco Employee

Hi Mike,

 

Please have a look at this link and follow the steps to disable SSLV3.

https://kb.wisc.edu/page.php?id=19734

 

Regards,

Kanwal

Note: Please mark answers if they are helpful.