| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| We recently performed a vulnerability assessment and found an issue with SNX SSLv2 implementation. Does anyone know how to force SNX to use only SSLv3 (TLSv1)? How can we configure SNX and disable SSLv2 support? __________________ Robert Meyeing,CISSP,CCMA 0017,CCSI,CCSE+NGX CCSE,CCSA,NCSA,NCSP Sr Info Security Consultant Intelligent Connections |
| |||
| Did you actually try and use SSLv1/2 or just a scanner? I know that several products start with an SSLv1 connection and then require TLS to actually complete the process. I forget the reason, but it has to do with some buggy browser implementations. So something like Nessus will report the SNX uses SSLv1 but in reality it doesn't. |
| |||
| We used a qualysguard scanner you are correct the scanner is simply reporting that sslv2 cipher is enabled and reported during ssl session neogation. We will test for actual sslv2 session capability next, thanks. __________________ Robert Meyeing,CISSP,CCMA 0017,CCSI,CCSE+NGX CCSE,CCSA,NCSA,NCSP Sr Info Security Consultant Intelligent Connections |
| |||
| Knew I had the message burried somewhere. I got this from one of the VPN product team folks a while ago Quote:
|
![]() |
| Thread Tools | |
| Display Modes | |
| |