This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Default httpd.conf for WAF enables insecure Protocols/Suites (TLS1, TLS1.1, 3DES) and enables Trace/Track on each firmware update

This is a continuation of https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/109122/failing-pci-scans-because-of-outdated-jquery-in-user-portal---is-there-a-fix/391323#391323 but a new thread was requested by LuCar Toni here: https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/109122/failing-pci-scans-because-of-outdated-jquery-in-user-portal---is-there-a-fix/392533#392533

 

 

On a fresh install of any firmware to a XG appliance the WAF settings allow insecure protocols and 3DES in addition to Trace/Track.  This has been a issue going back over two years (previous post: : https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/84480/failing-pci-scans---how-do-i-disable-tls-1-0-and-block-des-3des/368398#368398 )

 

Demonstration of what is happening.  After any firmware upgrade I have a PCI compliance scan done and get the following results:

 

 

I highlighted the failures on 3DES and TLS 1.0.  So I telnet in and check the appache httpd.conf file and this is whats in it:

 

 

Sure enough all those protocols are reenabled on each firmware upgrade.  I then manually edit that file to remove 3DES, TLSv1, TLSv1.1, and TraceTrack so it looks like this:

 

 

and restart the services (per instructions support gave me and I blogged about here). I then rescan and I no longer fail due to those items:

 

 

This is happening to multiple people on this forum and who have commented on my blog post.  Settings within the UI (mainly the "TLS setting") do not affect this behavior.

 

This is happening on 3 seperate XG boxes, one XG310 and a pair of XG125w.  All three were installed at different times and the last XG125W shipped with v17, the other two started with v16.  All three exhibit the same behavior on each firmware upgrade, the "secure" settings get wiped out and replaced by a "insecure set".




[locked by: FloSupport at 7:33 PM (GMT -8) on 11 Jan 2019]
Parents
  • Please build a new XG (using an older version) and then check the security settings.

    Then perform a restore of your configuration and check the security settings.

    Then allow the XG to install an update then check the security settings.

    Or build an new XG (older version), check the security settings, then run the update without your configuration.

    Ian

  • I'm not sure how this would help as it doesn't appear to affect virtual machines and the only people that have reported it, myself, , and a couple people through my website, were all on appliances.  And I'm definitely not doing this to my XG310 which is in production....I'm not risking it breaking and our network being down.  Or are you saying start up a virtual machine and load the backup to it?  I can do that but again I don't think its going to matter.

     

    I'd rather wait for to let me know what he found after I send him the documentation he asked for a couple weeks ago.

Reply
  • I'm not sure how this would help as it doesn't appear to affect virtual machines and the only people that have reported it, myself, , and a couple people through my website, were all on appliances.  And I'm definitely not doing this to my XG310 which is in production....I'm not risking it breaking and our network being down.  Or are you saying start up a virtual machine and load the backup to it?  I can do that but again I don't think its going to matter.

     

    I'd rather wait for to let me know what he found after I send him the documentation he asked for a couple weeks ago.

Children
No Data