- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-18-2022 10:53 AM
Hi,
One of our runs vulnerability Assessment on LAN Interface of the PA NGFW, And they are getting SSL/TLS Client-Initiated Renegotiation vulnerability, Please help me to remediate the same.
02-25-2022 07:31 AM
You don't give much detail... but this is probably a renegotiation to lower TLS versions 1.0/1.1 that are vulnerable. Look at which SSL/TLS Profile you are using on your PA management interface:
Device -> Setup -> Management -> General Settings -> SSL/TLS Service Profile == <xxx>
Then make sure your SSL/TLS profile is set to minimum TLS 1.2 (Note: Some older apps/browsers may not be able to handle this, so check if you are using the SSL/TLS profile for something else as well). Update the SSL/TLS profile:
Device -> Certificate Management -> SSL/TLS Service Profile -> <xxx> -> Min Version = 1.2
02-25-2022 07:31 AM
You don't give much detail... but this is probably a renegotiation to lower TLS versions 1.0/1.1 that are vulnerable. Look at which SSL/TLS Profile you are using on your PA management interface:
Device -> Setup -> Management -> General Settings -> SSL/TLS Service Profile == <xxx>
Then make sure your SSL/TLS profile is set to minimum TLS 1.2 (Note: Some older apps/browsers may not be able to handle this, so check if you are using the SSL/TLS profile for something else as well). Update the SSL/TLS profile:
Device -> Certificate Management -> SSL/TLS Service Profile -> <xxx> -> Min Version = 1.2
06-17-2022 06:45 AM
Hmmm.. My scans still show this as an issue after applying these settings.
06-17-2022 10:53 AM
Do you have multiple certificate SSL/TLS profiles and you are alerting on one other than associated with the management port? I.e. a different profile for your GlobalProtect Portals and Gateways which are not a minimum of TLS>=1.2?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!