Forum Discussion
Equivalent to SSLHonorCipherOrder on F5 LTM
Hi,
I aim wondering whether there is an equivalent setting for the F5 LTM Load balancing for SSLHonorCipherOrder
http://httpd.apache.org/docs/2.2/mod/mod_ssl.htmlsslhonorcipherorder
" SSLHonorCipherOrder
When choosing a cipher during an SSLv3 or TLSv1 handshake, normally the client's preference is used. If this directive is enabled, the server's preference will be used instead."
Is this an option, or is the Server's cipher preference order the default?
Thanks
2 Replies
- Brad_Parker
Cirrus
I believe F5 will choose the first matched cipher in the defined cipher suite that matches the highest level of encryption the client supports in the hello. This is why you can specify @strength, @speed, or your own ordering to beat fit your needs of strength versus SSL TPS. https://support.f5.com/kb/en-us/solutions/public/15000/200/sol15292.html
- Brad_Parker
Cirrus
There actually is an option that is equivalent, its called "Cipher server preference", and can be set in the client_ssl via the options list. This applies for clients that can only negotiate SSLv3/TLS1.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com