Forum Discussion
warbie
Feb 10, 2020Nimbostratus
Cipher Rule for just for TLS1.3
I'm running 15.0.1 on a pair for 2000s and I was trying to put a Cipher rule that just encompassed TLS1.3 so I can include with my other ciphers in a group. Seems like I can only do 1.3 with TLS13-AE...
- Feb 11, 2020
ltm cipher rule mozilla_modern_cipher_rule_v14 {
cipher TLSv1_3
dh-groups DEFAULT
signature-algorithms DEFAULT
}
This works for me in BIG-IP 14.1.x
wlopez
Feb 11, 2020Cirrocumulus
I haven't tried v15 yet.
But on v14.1, TLS 1.3 is not included by default on the client ssl profiles.
When you create the profile you need to disable the default option named 'No TLSv1.3' from the option list.
The combination of disabling that option and selecting the cipher group created with TLS1.3 is what actually activates the protocol on the client profile.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects