ܼ

ȼк

ץȥϢ

TCPΥॹ̵

ʲȼФб

  • ȼ
    generic-tcp-timestampTCP timestamp response

  • н
    TCPΥॹץץ̵ˤ롣


  • # config system global 
    (global) # set tcp-option disable 

SSLϢSSL VPN

٤μ夤Źζػ

ʲȼФб

  • ȼ
    ssl-3des-ciphersTLS/SSL Server Supports 3DES Cipher Suite

  • н
    ٤ι⤤ŹѤͤ¤롣

  • Ź涯٤
    # config system global 
    (global) # set strong-crypto enable 
    (global) # end
    
    # config vpn ssl settings 
    (settings) # set algorithm high 
    (settings) # end

ȼΤץȥ

ʲȼФб

  • ȼ
    ssl-cve-2011-3389-beastTLS/SSL Server is enabling the BEAST attack
    sslv3-cve-2014-3566-poodleTLS/SSL Server is enabling the POODLE attack
    sslv3-supportedTLS/SSL Server Supports SSLv3
    tls-dh-primesTLS/SSL Server Is Using Commonly Used Prime Numbers
    tlsv1_0-enabledTLS Server Supports TLS version 1.0
    tlsv1_1-enabledTLS Server Supports TLS version 1.1

  • н
    ȼΤץȥ(SSLv2SSLv3TLS1.01.1)Ѷػߤˤ롣

  • SSLv2SSLv3TLS1.0TLS1.1̵
    # config vpn ssl settings 
    (settings) # set sslv3 disable 
    (settings) # set sslv2 disable 
    (settings) # set tlsv1-0 disable 
    (settings) # set tlsv1-1 disable 
    (settings) # end

ȥå   Խ ʬ ʎގ̎ ź ʣ ̾ѹ   ǽ   إ   ǽRSS
Last-modified: 2017-06-07 () 09:45:12 (1894d)