SV-242575r714035_rule
V-242575
SRG-NET-000062-NAC-000340
CSCO-NC-000010
CAT I
10
Configure ISE so that only TLS 1.2 is enabled:
From the Web Admin portal:
1. Navigate to Administration >> System >> Settings >> Security Settings.
2. Ensure "Allow TLS1.0", "Allow TLS1.1", and "Allow legacy unsafe TLS renegotiation for ISE as a client" are unchecked.
Verify that only TLS 1.2 is enabled.
From the Web Admin portal:
1. Navigate to Administration >> System >> Settings >> Security Settings.
2. Ensure "Allow TLS1.0", "Allow TLS1.1", and "Allow legacy unsafe TLS renegotiation for ISE as a client" are unchecked.
If TLS 1.0 or 1.1 is enabled, this is a finding.
V-242575
False
CSCO-NC-000010
Verify that only TLS 1.2 is enabled.
From the Web Admin portal:
1. Navigate to Administration >> System >> Settings >> Security Settings.
2. Ensure "Allow TLS1.0", "Allow TLS1.1", and "Allow legacy unsafe TLS renegotiation for ISE as a client" are unchecked.
If TLS 1.0 or 1.1 is enabled, this is a finding.
M
5383