DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

SSL VPN failing PCI compliance scan

More
25 Apr 2016 12:49 #85995 by dmcsparron
Replied by dmcsparron on topic Re: SSL VPN failing PCI compliance scan
We are also having the same issue. Does anyone have a fix for this?

Please Log in or Create an account to join the conversation.

More
25 Apr 2016 14:42 #85997 by admin
Replied by admin on topic Re: SSL VPN failing PCI compliance scan
I don't get the same result (mine is fine) but may not have the same model/firmware.
Best to ask support and confirm exactly what firmware and model you're using as I don't think this is a problem if set up correctly.



Forum Administrator

Please Log in or Create an account to join the conversation.

  • jon2016
  • Topic Author
  • Offline
  • New Member
  • New Member
More
25 Apr 2016 14:47 #85998 by jon2016
Replied by jon2016 on topic Re: SSL VPN failing PCI compliance scan
Sorry meant to post this ages ago, hope it helps some of you.

Please follow the procedure below to disable SSL VPN service:
- Make sure that SSL VPN is enabled, allow reboot
- Change HTTPS management port to e.g. 4443, allow reboot
- Change SSL VPN port to 4443
- Disable SSL VPN in remote access control menu, allow reboot
- Return HTTPS management to 443, allow reboot

It seems a bit crazy but it works!

Please Log in or Create an account to join the conversation.

More
02 Nov 2016 12:48 #87152 by dansw
Replied by dansw on topic Re: SSL VPN failing PCI compliance scan
Hi, I have finally fallen foul of this but I am actually using SSL VPN to get to our LAN from outside so need it enabled. How do I sort this out without switching SSL VPN off?

As with the OP, the PCI scan is also complaining of using TLS 1.0 even though I have upgraded firmware to the latest (3.6.8.4_sb_232201) which is meant to be using TLS 1.1.

Thanks

Dan

Please Log in or Create an account to join the conversation.

More
03 Nov 2016 10:30 #87155 by admin3
Replied by admin3 on topic Re: SSL VPN failing PCI compliance scan
Check the DrayTek UK site for 3.6.8.5 firmware, which is now available on the downloads page, it adds an option on the [System Maintenance] > [Management] page to enable/disable TLS 1.0/1.1/1.2.



Forum Administrator

Please Log in or Create an account to join the conversation.

More
07 Nov 2016 11:28 #87200 by dansw
Replied by dansw on topic Re: SSL VPN failing PCI compliance scan
Thanks, just noticed that. They must have released it the day after I downloaded what I thought was the most recent!

Please Log in or Create an account to join the conversation.

Moderators: Sami