目次
以下の脆弱性に対する対応。
generic-tcp-timestamp | TCP timestamp response |
# config system global (global) # set tcp-option disable
以下の脆弱性に対する対応。
ssl-3des-ciphers | TLS/SSL Server Supports 3DES Cipher Suite |
# config system global (global) # set strong-crypto enable (global) # end # config vpn ssl settings (settings) # set algorithm high (settings) # end
以下の脆弱性に対する対応。
ssl-cve-2011-3389-beast | TLS/SSL Server is enabling the BEAST attack |
sslv3-cve-2014-3566-poodle | TLS/SSL Server is enabling the POODLE attack |
sslv3-supported | TLS/SSL Server Supports SSLv3 |
tls-dh-primes | TLS/SSL Server Is Using Commonly Used Prime Numbers |
tlsv1_0-enabled | TLS Server Supports TLS version 1.0 |
tlsv1_1-enabled | TLS Server Supports TLS version 1.1 |
# config vpn ssl settings (settings) # set sslv3 disable (settings) # set sslv2 disable (settings) # set tlsv1-0 disable (settings) # set tlsv1-1 disable (settings) # end