For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

dabance's avatar
dabance
Icon for Altocumulus rankAltocumulus
Jan 13, 2020

Disable selected ciphers.

Below result of ssllab scan for one of the vip . We would like to disabled selected ciphers (TO DISABLE) in addition to present filter and would like to allow the rest

 

Currently i have DEFAULT:!RC4-SHA:!DES-CBC3-SHA:!ECDHE-RSA-DES-CBC3-SHA cipher restriction under client ssl.

 

What additional filter i can include to achieve this?

 

TLSv1.0:

   server selection: enforce server preferences

    RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA

    RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA

 

   TO DISABLE (key: RSA) RSA_WITH_AES_128_CBC_SHA

   TO DISABLE (key: RSA) RSA_WITH_AES_256_CBC_SHA

   TO DISABLE (key: RSA) RSA_WITH_CAMELLIA_128_CBC_SHA

   TO DISABLE (key: RSA) RSA_WITH_CAMELLIA_256_CBC_SHA

 

    RSA) DHE_RSA_WITH_AES_128_CBC_SHA

    RSA) DHE_RSA_WITH_AES_256_CBC_SHA

    RSA) DHE_RSA_WITH_CAMELLIA_128_CBC_SHA

    RSA) DHE_RSA_WITH_CAMELLIA_256_CBC_SHA

 TLSv1.1: idem

 TLSv1.2:

   server selection: enforce server preferences

    RSA) ECDHE_RSA_WITH_AES_128_GCM_SHA256

    RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA

    RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA256

    RSA) ECDHE_RSA_WITH_AES_256_GCM_SHA384

    RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA

    RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA384

 

   TO DISABLE RSA) RSA_WITH_AES_128_GCM_SHA256

   TO DISABLE RSA) RSA_WITH_AES_128_CBC_SHA

   TO DISABLE RSA) RSA_WITH_AES_128_CBC_SHA256

   TO DISABLE RSA) RSA_WITH_AES_256_GCM_SHA384

   TO DISABLE RSA) RSA_WITH_AES_256_CBC_SHA

   TO DISABLE RSA) RSA_WITH_AES_256_CBC_SHA256

   TO DISABLE RSA) RSA_WITH_CAMELLIA_128_CBC_SHA

   TO DISABLE RSA) RSA_WITH_CAMELLIA_256_CBC_SHA

 

 

   RSA) DHE_RSA_WITH_AES_128_GCM_SHA256

   RSA) DHE_RSA_WITH_AES_128_CBC_SHA

   RSA) DHE_RSA_WITH_AES_128_CBC_SHA256

   RSA) DHE_RSA_WITH_AES_256_GCM_SHA384

   RSA) DHE_RSA_WITH_AES_256_CBC_SHA

   RSA) DHE_RSA_WITH_AES_256_CBC_SHA256

   RSA) DHE_RSA_WITH_CAMELLIA_128_CBC_SHA

   RSA) DHE_RSA_WITH_CAMELLIA_256_CBC_SHA

 

 

Current default client cipher on BIGIP

 

2 Replies

  • Which version of F5 you are running in environment?

    What rating you are seeing currently and expected rating in SSL Labs?

     

    • dabance's avatar
      dabance
      Icon for Altocumulus rankAltocumulus

      Rating is B , Not keen on making it to a better rating, but need to disable selected ciphers as requested.

      Version : 13.1.0.7 (Virtual)