Does ZyWall USG 20W support AES and 3DES and why is it absent on my router
Symptoms:
- I can only choose DES encryption in VPN Gateway/Connection settings.
- Router(config)# show ip http server secure cipher-list only shows RC4 and DES ciphers
- When trying to enable cipher suite using CLI I get:
- I can only choose DES encryption in VPN Gateway/Connection settings.
- Router(config)# show ip http server secure cipher-list only shows RC4 and DES ciphers
- When trying to enable cipher suite using CLI I get:
Router(config)# ip http secure-server cipher-suite aes 3des des rc4
% Ignore AES or 3DES
and I am still left with DES and RC4.
I've tried all available Firmware and result is the same. How can I enable AES and 3DES?
P.S.
One more symptom is that one can not log in via web interface from any modern browser: ERR_SSL_VERSION_OR_CIPHER_MISMATCH. The only way I could bypass that was using old version of FireFox (v43). I also tried the latest TLS1.2 firmware, 330BDR9ITS-WK48-r74988 but this did not solve the problem. The only cipher-suites that are available are DES and RC4.
and I am still left with DES and RC4.
I've tried all available Firmware and result is the same. How can I enable AES and 3DES?
P.S.
One more symptom is that one can not log in via web interface from any modern browser: ERR_SSL_VERSION_OR_CIPHER_MISMATCH. The only way I could bypass that was using old version of FireFox (v43). I also tried the latest TLS1.2 firmware, 330BDR9ITS-WK48-r74988 but this did not solve the problem. The only cipher-suites that are available are DES and RC4.
0
Accepted Solution
-
Hi, thanks for the link but I have looked into it before.
These commands will disable DES and RC4. However I only have DES and RC4 in my cipher-suite!
If I disable DES and RC4 then nothing will work at all.
I found the solution though:
Router(config)# crypto algorithm-hide disable
enables AES and 3DES.0
All Replies
-
https://kb.zyxel.com/KB/searchArticle!gwsViewDetail.action?articleOid=014475&lang=EN
You can use SSH or console port to achieve that.0 -
Hi, thanks for the link but I have looked into it before.
These commands will disable DES and RC4. However I only have DES and RC4 in my cipher-suite!
If I disable DES and RC4 then nothing will work at all.
I found the solution though:
Router(config)# crypto algorithm-hide disable
enables AES and 3DES.0 -
Thanks for sharing. I'd don't use RC4 but... it's only me0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 150 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 267 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 41 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 388 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 74 Security Highlight