Update your ASA's cipher suite

Update the TLS cipher suites on your ASA to ensure secure communication by configuring specific encryption protocols that meet your security requirements.

You need to modify the TLS cipher suite configuration when strengthening the security posture of your ASA device or when compliance requirements mandate specific encryption standards.

Procedure


Step 1

Connect to the ASA using SSH.

Step 2

Once connected to the ASA, elevate your privileges to global configuration mode.

Your prompt should look like this: asaname(config)#

Step 3

At the prompt, enter a command similar to this:

Example:

ssl cipher tlsv1.2 custom "ECDHE-RSA-AES128-GCM-SHA256 ECDHE-ECDSA-AES128-GCM-SHA256 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 DHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES128-SHA256 DHE-RSA-AES128-SHA256 ECDHE-RSA-AES256-SHA384 DHE-RSA-AES256-SHA384 ECDHE-RSA-AES256-SHA256 DHE-RSA-AES256-SHA256"
Note

The cipher suites this command configures your ASA to support are contained between quotes and after the word custom. In this command, the cipher suites specified begin with ECDHE-RSA-AES128-GCM-SHA256 and end with DHE-RSA-AES256-SHA256. When you enter the command on your ASA, remove any cipher suites you know your ASA will not support.

Step 4

After you submit the command, enter write memory at the prompt to save the local configuration.

Example:

asaname(config)#write memory

The ASA is now configured with the specified TLS cipher suites, and the configuration has been saved to memory.