If all remote entities which are connected over TLS support secure
renegotiation (RFC 5746), then enable to enforce it. If a remote entity
does not support the RFC the renegotiation in some scenarios even the
establishment will fail and the connection is released.
This behavior can be changed by checkbox:
-
Configuration > Security > Signaling and Payload Encryption (SPE)
> SPE Security Setup > TLS Re-Keying Parameters > Enforce Secure
Renegotiation (RFC 5746)