Configure a client SSL profile that supports TLS 1.2 and 1.3, and a separate server SSL profile that supports TLS 1.1 and 1.0.
I the full proxy architecture, the client SSL profile works on the client side of the proxy and acts as the server to the TLS session. The client sends a Client Hello message and list of supported ciphers, and the server (BIG-IP) picks one of the ciphers to continue the TLS handshake. The server SSL profile works on the server side of the proxy and acts as the client to the TLS session. It sends a Client Hello to the server with its list of supported ciphers. This list comes from the cipher string defined in the server SSL profile.