How do I remove diffie-hellman-group1-sha1 from SSH on mgmt port? And how to push it via Panorama?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How do I remove diffie-hellman-group1-sha1 from SSH on mgmt port? And how to push it via Panorama?

L1 Bithead

Hi,

How do I remove diffie-hellman-group1-sha1 from SSH on mgmt port? I've removed the CBC ciphers, but my vulnerability scanner is still showing that diffie-hellman-group1-sha1 is still available for SSH.

 

I'd also like to know how I enforce SSH server ciphers or other parameters on management ports via Panorama. I have about 60+ firewalls of various Palo models, with 8.1.13 installed. We use Panorama on appliances. 

 

Having to send CLI commands to these devices is going to be an issue. I imagine editing the templates we use for the firewalls to add CLI changes may be possible, but what's the best practice way to push SSH management server changes to a pile of firewalls?

 

Note: I've seen that with 9.1 (and maybe 9.0) we can modify the kex algorithms available. It doesn't seem to be on 8.1.13. I just upgraded everything to 8.1.13, so I'm disinclined to update them all AGAIN! 😄 

 

I do need to know the best way to get a CLI change to all sites. I'd expect I'd need to modify a template, one of the ones I currently use, but then can I add CLI changes to templates we've created in Panorama, and can the changes be seen on the Pano GUI when someone looks?

 

Regards,

Ambi

3 REPLIES 3

Cyber Elite
Cyber Elite

I have, thanks. It does work, except i need 9.0 or 9.1 to enable the KEX algorithms to be selected manually, to remove sha1.

 

My question is now, that I have a number of changes to the management port to do, how do I push them to 60+ firewalls in Panorama? I'd want to add these to an existing template. But maybe a new template that's "related" to some existing template?

 

Thanks,


Ambi

the link you provided shows that it has been deleted when you go to it.

  • 6222 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!