SSL/TLS Client-Initiated Renegotiation Vulnerability in NGFW LAN Int

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SSL/TLS Client-Initiated Renegotiation Vulnerability in NGFW LAN Int

L4 Transporter

Hi, 

 

One of our runs vulnerability  Assessment on LAN Interface of the PA NGFW, And they are getting SSL/TLS Client-Initiated Renegotiation vulnerability, Please help me to remediate the same. 

Snow
1 accepted solution

Accepted Solutions

L6 Presenter

You don't give much detail... but this is probably a renegotiation to lower TLS versions 1.0/1.1 that are vulnerable. Look at which SSL/TLS Profile you are using on your PA management interface:

Device -> Setup -> Management -> General Settings -> SSL/TLS Service Profile == <xxx>

 

Then make sure your SSL/TLS profile is set to minimum TLS 1.2 (Note: Some older apps/browsers may not be able to handle this, so check if you are using the SSL/TLS profile for something else as well). Update the SSL/TLS profile:

Device -> Certificate Management -> SSL/TLS Service Profile -> <xxx> -> Min Version = 1.2

 

View solution in original post

4 REPLIES 4

L6 Presenter

You don't give much detail... but this is probably a renegotiation to lower TLS versions 1.0/1.1 that are vulnerable. Look at which SSL/TLS Profile you are using on your PA management interface:

Device -> Setup -> Management -> General Settings -> SSL/TLS Service Profile == <xxx>

 

Then make sure your SSL/TLS profile is set to minimum TLS 1.2 (Note: Some older apps/browsers may not be able to handle this, so check if you are using the SSL/TLS profile for something else as well). Update the SSL/TLS profile:

Device -> Certificate Management -> SSL/TLS Service Profile -> <xxx> -> Min Version = 1.2

 

L4 Transporter

Thanks @Adrian_Jensen , 

 

I have resolved with the same way. 

Snow

L0 Member

Hmmm.. My scans still show this as an issue after applying these settings.

L6 Presenter

Do you have multiple certificate SSL/TLS profiles and you are alerting on one other than associated with the management port? I.e. a different profile for your GlobalProtect Portals and Gateways which are not a minimum of TLS>=1.2?

  • 1 accepted solution
  • 6439 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!