Forum Discussion
F5 BIG IP LTM - SSL CIPHERS
Hello all, I have an F5 BIG IP LTM running version 11.2.1. I am running PCI on my network and was receiving bad scores until I figured out that I had to change the SSL Profile Cipher string.
I changed it to:
TLSv1_2:TLSv1_1:TLSv1:@speed:!MD5:!EXPORT:!DES:!DHE:!EDH:!RC4:!ADH
I am now receiving an A- on the PCI scan which is great but I am failing on "Forward Secrecy". I am having trouble figuring out how to fix this. Any help would be greatly appreciated.
1 Reply
- Cody_Green
Employee
This DevCentral article should have what you need to get a better score - LogJams, DHE Parameters, and Other Obstacles to TLS Excellence
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com