DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Disabled TLS and have locked myself out of 2860 :o(
- toff
- Topic Author
- Offline
- New Member
Less
More
- Posts: 5
- Thank yous received: 0
20 Sep 2018 02:31 #92969
by toff
Disabled TLS and have locked myself out of 2860 :o( was created by toff
Hi all,
I have been using HackerGuard to run a PCI compliance test on the public IP of a DrayTek 2860 (firmware last brought up-to date about 2-3 months ago after the security scare).
The network scan kept coming back a as failure because HackerGuard detects old versions of TLS on the router. I had already unticked TLS version 1.x in the management page but the scan still came back as a fail.
I finally unticked TLS 1.2 (so no TLS options were ticked) and saved the config... now I can't get back into the router (I'm trying to access from the LAN via TeamViewer - the router is still routing traffic normally).
I'm pretty certain Telnet / SSH are disabled on this 2860. Is my only hope of getting back into the router (whilst preserving the config) to disable all cipher suits in my browser (not sure if this is possible) or connect from a LAN PC running an old version of Windows / with an old browser that doesn't demand TLS?
Or is there no choice but to reset the router to factory defaults?
Any advice appreciated.
Toff
I have been using HackerGuard to run a PCI compliance test on the public IP of a DrayTek 2860 (firmware last brought up-to date about 2-3 months ago after the security scare).
The network scan kept coming back a as failure because HackerGuard detects old versions of TLS on the router. I had already unticked TLS version 1.x in the management
I finally unticked TLS 1.2 (so no TLS options were ticked) and saved the config... now I can't get back into the router
I'm pretty certain Telnet / SSH are disabled on this 2860. Is my only hope of getting back into the router (whilst preserving the config) to disable all cipher suits in my browser (not sure if this is possible) or connect from a LAN PC running an old version of Windows / with an old browser that doesn't demand TLS?
Or is there no choice but to reset the router to factory defaults?
Any advice appreciated.
Toff
Please Log in or Create an account to join the conversation.
- spellbinder
- Offline
- Junior Member
Less
More
- Posts: 64
- Thank yous received: 0
23 Sep 2018 16:08 #93014
by spellbinder
Replied by spellbinder on topic Re: Disabled TLS and have locked myself out of 2860 :o(
Hello
You disabled TLS v1.2 which is the highest version... You should only diable SSL3.0 and TLS1.0, leaving TLS 1.1 and 1.2 activated
What you can do if possible is to access the LAN remotely and access the web page of the router via HTTP and reactivate the settings
You disabled TLS v1.2 which is the highest version... You should only diable SSL3.0 and TLS1.0, leaving TLS 1.1 and 1.2 activated
What you can do if possible is to access the LAN remotely and access the web page of the router via HTTP and reactivate the settings
Please Log in or Create an account to join the conversation.
- manicguitarist
- Offline
- Junior Member
Less
More
- Posts: 45
- Thank yous received: 0
07 Oct 2018 19:49 #93117
by manicguitarist
Replied by manicguitarist on topic Re: Disabled TLS and have locked myself out of 2860 :o(
Or fire up a virtual machine of Windows XP and use an old browser to get to it?
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek