Disable TLS 1.1 Support

Description

You can  disable the support for old and insecure SSL/TLS versions to improve the security of your network.

  • The SonicWall management interface can now be accessed from a browser using SSLv3, TLS 1.0, TLS 1.1 or TLS 1.2.
  • The SonicWall SSL-VPN feature can also be accessed using these protocols.
  • The DPI-SSL feature supports all the protocols above.

Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

  1. Login to the SonicWall management and then go to diag page through the URL : https://{IP_ADDRESS}/sonicui/7/m/mgmt/settings/diag
    EXAMPLE: From dashboard page after login, change the URL at top from https://192.168.168.168/sonicui/7/m/dashboard/overview/status/device to https://192.168.168.168/sonicui/7/m/mgmt/settings/diag
  2. Click Internal Settings.
  3. Search for Enable TLS compatible mode and disable it if enabled.
  4. You can also disable TLS 1.1 from the diag page.

     CAUTION: TLS 1.1 is still very used on the web.

                        Image

 

Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.

  1. Login to the SonicWall management and then replace the word main with the word diag in the URL.
    EXAMPLE: https://192.168.168.168/main.html will become https://192.168.168.168/diag.html.
  2. Click Internal Settings.
  3. Search for Enable TLS compatible mode and disable it if enabled.
  4. You can also disable TLS 1.1 from the diag page.
     CAUTION: TLS 1.1 is still very used on the web.

    Image

 

Resolution for SonicOS 6.2 and Below

The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.

  1. Login to the SonicWall management and then replace the word main with the word diag in the URL.

    EXAMPLE: https://192.168.168.168/main.html will become https://192.168.168.168/diag.html).

  2. Click Internal Settings.
  3. Search for Enable TLS compatible mode and disable it if enabled.
  4. You can also disable TLS 1.1 from the diag page.
    CAUTION: TLS 1.1 is still very used on the web.

    Image

NOTE:  On Previous firmware versions you can find a screen like the following. Make sure Disable SSLv3 and Disable TLSv1 are checked. There is no option to disable TLSv1.1 on older firmware versions.
Image

Related Articles

  • TOTP based two-factor authentication for management by Admin user using SonicOS API
    Read More
  • Two-factor authentication using TOTP for Management by User with admin privileges
    Read More
  • How do I configure Two-factor authentication for the Admin login with TOTP?
    Read More
not finding your answers?
was this article helpful?