Tuesday, January 26, 2021

Log and Report Weak Cipher Traffic On The Network?

We plan to enforce TLS 1.2 as a minimum on the domain.

What methods are available to log and report TSL 1.1 or anything else weaker is being used so the offenders can be remediated before enforcement is enabled?

Can some kind of network scan be done that can create readable reports of senders and receivers of this traffic? We want to be able to use the report to contact server and app admins to tell them to reocnfigure/update their systems before the date enforcement starts.

Do any Cisco routers, switches or IDS have this type of functionality built in?



No comments:

Post a Comment