Cisco Cisco Web Security Appliance S170 사용자 가이드

다운로드
페이지 466
 
22-23
AsyncOS 8.8 for Cisco Web Security Appliances User Guide
 
Chapter 22      Perform System Administration Tasks
  SSL Configuration
Manually Setting the System Date and Time in the GUI
Step 1
Choose System Administration > Time Settings.
Step 2
Click the Select Set Time Manually radio button.
Step 3
Set the date and time.
Step 4
Click Submit.
SSL Configuration 
For enhanced security, you can enable and disable SSLv3 for several services. Services with SSLv3 
disabled will use TLSv1.0.
Step 1
Choose System Administration > SSL Configuration.
Step 2
Click Edit Settings
Step 3
Check the corresponding box to enable SSLv3 for these services:
Appliance Management Web User Interface – changing this setting will disconnect all active 
user connections.
Proxy Services – Includes HTTPS Proxy and Credential Encryption for Secure Client.
Secure LDAP Services – Includes Authentication, External Authentication, SaaS SSO, and 
Secure Mobility.
Update Service 
Step 4
Click Submit.
Note
You also can use the 
sslv3config
 CLI command to enable or disable these features. Further, you can 
use the 
sslconfig
 command, 
ECDHE
 option, to enable or disable ECDHE cipher use for HTTPS proxy and 
LDAP services. 
Certificate Management
The appliance uses digital certificates to establish, confirm and secure a variety of connections. The 
Certificate Management page lets you view and update current certificate lists, manage trusted root 
certificates, and view blocked certificates.
Related Topics