Forum Discussion
gdoyle
Cirrostratus
May 19, 2016Custom Response Upon Denial with iRule.
We created an irule which denies a user access if they are not using TLS 1.1 or greater (so TLS1.0 or no TLS). We would like a custom message, and although it is in the iRule, that is not the message...
Yann_Desmarest
Cirrus
May 23, 2016Hi,
You can use one of the irules provided above and add TLS1.0 ciphers in the cipher list. For example, you can do the following in the cipher list of your client ssl profile :
DEFAULT:TLSv1- gdoyleMay 23, 2016
Cirrostratus
I added that cipher and then tried each of the irules listed above, but I am at the same result. - Yann_DesmarestMay 23, 2016
Cirrus
Hi, can you explain the behavior ? I tested the same configuration on my lab in multiples versions and everything work as expected - gdoyleMay 24, 2016
Cirrostratus
The TLSv1 in the cipher and using any of the irules that y'all were kind enough to provide above, I receive the same message. Firefox tells the testers that the website owner has configured the site improperly. IE says that in order to access the site they will have to enable TLS 1.0, 1.1, or 1.2. It is basically acting as if no irule exists at all and immediately being denied and receiving the default message from the browser. This is even with TLS1 allowed in the ciphers and the irule in place.. It is odd. I'm wondering now if there is just another way, via ifile or something else, to go about doing this check and redirecting them to a notification page? Thoughts? - Yann_DesmarestMay 24, 2016
Cirrus
The problem is that if the browser decide that the connection is untrusted or there is a cipher mismatch, you can't do anything on the BIG-IP. You can do something only if the ssl handshake works fine. In your case, it sounds that there is a cipher mismatch between your VS and the browser used for testing. Please note that if the testers add fiddler or other debugging tools, it can change the behavior of the connection. - gdoyleMay 24, 2016
Cirrostratus
They are developers, so they may have something like that installed, but I have tested myself in Firefox and receive the same error messages. I understand what you're saying about the SSL handshake, and I believe that is the issue too; that is why I am now wondering if something like a redirect via irule/ifile would work better for this.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects