<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable Cipher Suite in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342521#M85838</link>
    <description>&lt;P&gt;Ok.. I didn't know it as an option starting version 8.&lt;/P&gt;&lt;P&gt;I ran this command on our panorama(9.0.9) and only thing i see failing in ssllabs test is renegotiation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set template PA1 config vsys vsys1 ssl-tls-service-profile GP certificate VPN protocol-settings min-version tls1-2 enc-algo-aes-128-cbc no enc-algo-3des no enc-algo-aes-256-cbc no auth-algo-sha1 no enc-algo-rc4 no max-version max keyxchg-algo-rsa no&lt;/P&gt;</description>
    <pubDate>Thu, 06 Aug 2020 16:38:29 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2020-08-06T16:38:29Z</dc:date>
    <item>
      <title>Disable Cipher Suite</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342268#M85802</link>
      <description>&lt;P&gt;As of the pen test via SSL LAB&amp;nbsp; i was observed that less secure ciphers like DES, RC4 were supported by global protect portal ,so that i have disable the all the weak cipher suite and it's successfully done but the when i disable CBC-256 Suite when i commit it got this error&amp;nbsp; Please Suggest&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Joshan_Lakhani_0-1596646238785.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27169iE6247E0DE7D85424/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Joshan_Lakhani_0-1596646238785.png" alt="Joshan_Lakhani_0-1596646238785.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;protocol-settings {&lt;/P&gt;&lt;P&gt;&amp;nbsp; min-version tls1-2;&lt;/P&gt;&lt;P&gt;&amp;nbsp; max-version max;&lt;/P&gt;&lt;P&gt;&amp;nbsp; enc-algo-aes-128-cbc no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; enc-algo-aes-128-gcm no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; auth-algo-sha256 no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; auth-algo-sha384 no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; enc-algo-aes-256-cbc no;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 16:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342268#M85802</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-05T16:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Cipher Suite</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342483#M85831</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130663"&gt;@Joshan_Lakhani&lt;/a&gt;&amp;nbsp;Curious how do you block ciphers. I have the certificate imported and then creates SSL/TLS service profile set to minimum 1.2. Where do e select ciphers.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 15:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342483#M85831</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-08-06T15:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Cipher Suite</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342521#M85838</link>
      <description>&lt;P&gt;Ok.. I didn't know it as an option starting version 8.&lt;/P&gt;&lt;P&gt;I ran this command on our panorama(9.0.9) and only thing i see failing in ssllabs test is renegotiation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set template PA1 config vsys vsys1 ssl-tls-service-profile GP certificate VPN protocol-settings min-version tls1-2 enc-algo-aes-128-cbc no enc-algo-3des no enc-algo-aes-256-cbc no auth-algo-sha1 no enc-algo-rc4 no max-version max keyxchg-algo-rsa no&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 16:38:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342521#M85838</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-08-06T16:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Cipher Suite</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342559#M85846</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please follow this KB&amp;nbsp; to disable weak cipher suite. As these cipher suite can be disable from 8.1 onward version before 8.1 you can not disable weak cipher suite.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmqeCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmqeCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 18:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/342559#M85846</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-06T18:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Cipher Suite</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/343311#M85952</link>
      <description>&lt;P&gt;As I disable all other weak&amp;nbsp; cipher suite but the when i disable CBC-256 i got the error. As i use TLS1.2&amp;nbsp; 3rd party certificate.Please suggest&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 17:00:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-cipher-suite/m-p/343311#M85952</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-11T17:00:52Z</dc:date>
    </item>
  </channel>
</rss>

