This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM TLSv1.2 Support ??

Hello,

 

I use Sophos UTM Version 9.702-1 and found this article here for PCI DSS Compliance https://community.sophos.com/kb/en-us/127420 I'm wondering, is the actual Firmware Version of the UTM not yet supporting TLSv1.2 or higher?



This thread was automatically locked due to age.
  • TLS 1.2 is supported in UTM 9.7

     

    here's snapshot from smtp TLS settings

     

  • Found this to remove TLSv1.1 from from Webadmin and User Portal, what worked for me.

    root login:

    1.  cc
    2.  webadmin
    3.  tls_protocols$
    4.  =+TLSv1.2
    5.  exit

    Does anyone know, how to change the Ciper Suites? Are there any other Services what has to be changed manually to TLSv1.2 ?

     

    Thx

  • I hadn't thought of that, so thanks!  Rather than use cc interactively, I prefer to use the command line as root:

    cc set webadmin tls_protocols +TLSv1.2

    You can see the current ciphers with:

    cc get webadmin tls_ciphers

    What would you want to change?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hello Bob,

     

    thanks for the information, Just would like to know, what would be a strong Ciper Suite for TLSv1.2 for webadmin, and for WebProxy? 

     

    Thx

    Sally

  • My guess is that the current choices are the best.  When we dealt with POODLE in 2014, I think Sophos then made permanent changes to the ciphers.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA