I have some VPX's being flagged for Sweet32. I have removed any DES related ciphers from the cipher group we use yet Im still getting flagged in SOME VPX's, not all. I don't have to remove the DES cipher from the default cipher groups I hope.

Which firmware version are you on?

You won't be able to edit the default cipher group; you can create a custom group with the ciphers to support and then bind those in place of the default cipher group.  IF you have your own cipher group bound, you should not be using the default cipher group.


Can you tell which IPs are being flagged, so you know which vserver or managment ip you need to adjust the cipher groups for?  (Management IPs would have to be modified via the internal services tab on a per management service basis.)

