cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Cyber Elite
Cyber Elite

Hello,

I'm sure its not the answer you would like, however I would suggest rebuilding all the tunnels to FIPS 140-2 standards. i.e. DH groups 14,19 or 20, SHA256 and AES 256 ( i know lower numbers are still FIPS, however I suggest 256 or higher if supported. Once rebuilt, then worry about removing the weaker ciphers from the devices. Failure to do so will, like you found out, cause downtime.

 

Regards, 

Who rated this post