For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

mnilan_178954's avatar
mnilan_178954
Icon for Nimbostratus rankNimbostratus
Aug 04, 2015

F5 BIG IP LTM - SSL CIPHERS

Hello all, I have an F5 BIG IP LTM running version 11.2.1. I am running PCI on my network and was receiving bad scores until I figured out that I had to change the SSL Profile Cipher string.

 

I changed it to:

 

TLSv1_2:TLSv1_1:TLSv1:@speed:!MD5:!EXPORT:!DES:!DHE:!EDH:!RC4:!ADH

 

I am now receiving an A- on the PCI scan which is great but I am failing on "Forward Secrecy". I am having trouble figuring out how to fix this. Any help would be greatly appreciated.