DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

SSL/TLS PCI DSS 2820vn

  • clintoncards
  • Topic Author
  • User is blocked
  • User is blocked
More
24 Nov 2015 11:41 #1 by clintoncards
SSL/TLS PCI DSS 2820vn was created by clintoncards
Can someone please explain to me what Updated SSL for CVE-2014-0224 actually means in firmware 3.3.7.5 for the 2820vn.

We have a large estate of 2820vn's running below the above firmware. We are currently going through the PCI DSS process and have been advised that when accessing the router through https that we are not secure enough.

When using Firefox with a router running 3.3.7.5 it still says unable to connect securely as it is still using SSL 3.0.

Is there any way to be secure using the 2820vn or are they too old for these newer protocols.

Thanks in advance.

Please Log in or Create an account to join the conversation.

More
25 Nov 2015 10:40 #2 by voodle
Replied by voodle on topic Re: SSL/TLS PCI DSS 2820vn
From what I can see it's just the 2830, 2930 and later stuff that gets TLS support. Why not disable HTTP / HTTPS management (or remote management, in general?) and access it via VPN tunnel instead. That's probably the most secure way of doing it at this stage with the 2820.

Please Log in or Create an account to join the conversation.

  • clintoncards
  • Topic Author
  • User is blocked
  • User is blocked
More
26 Nov 2015 11:46 #3 by clintoncards
Replied by clintoncards on topic Re: SSL/TLS PCI DSS 2820vn
Thanks Voodle. I have tried doing this but keep getting username or password error when accessing from my PC over the WAN. Any idea's off the top of your head?

Thanks Dave

Please Log in or Create an account to join the conversation.

  • clintoncards
  • Topic Author
  • User is blocked
  • User is blocked
More
26 Nov 2015 14:33 #4 by clintoncards
Replied by clintoncards on topic Re: SSL/TLS PCI DSS 2820vn
Figured it out but it doesn't help me as I only want secured access to the router landing page, thus far I have full access to every device on that lan which introduces a whole set of different problems for me.

Please Log in or Create an account to join the conversation.