Hi all,
During some testing with a USG110 and USG60 I allowed HTTPS access for management from the LAN (not WAN).
I followed the steps from ZyXEL's KB article on enabling strong-cipher suite:
Their KB:
http://kb.zyxel.com/KB/searchArticle!gwsViewDetail.action?articleOid=014475&lang=EN
The command they use:
ip http secure-server strong-cipher
However, after running that, I still couldn't get them to support/require TLS 1.2.
Google Chrome just connected and told me it was a TLS 1.0 connection.
Internet Explorer, with support for TLS 1.0 and 1.1 turned off, refused to connect with TLS 1.2.
Per older posts I tried the following CLI command:
ip http secure-server cipher-suite rc4
But then neither Chrome nor IE would connect
Am I missing something? Any suggestions on how to force TLS 1.2 with the USG110 or USG60?
↧