Forum Discussion
How to turn off TLS1.0 – and only allow TLS1.1 and TLS1.2 on LTM 2000s
When we implement the new F5 load balancers and proxies, we have to turn off TLS1.0 – we will only allow TLS1.1 and TLS1.2
3 Replies
- Hannes_Rapp
Nimbostratus
Create a new clientssl profile where you specify a custom cipher-string, keep the other settings as default. You can name this as 'profile_clientssl_base'.
If all you want is to disable TLSv1.0, and keep the rest as default, you can use
as your custom string. When done, this profile can be reused as your Parent Profile for all the other clientssl profiles you create in the future.DEFAULT:!TLSv1If your concern is with the upcoming PCI DSS 3.1 requirements (will be enforced in June 2016), have a look at here https://devcentral.f5.com/questions/pci-cipher-set. You should check out the second answer which is not User Accepted, if you don't want to disable more cipher suites than required.
- tatmotiv
Cirrostratus
Also, have a look at this document which is totally recommended reading: https://f5.com/Portals/1/Premium/Architectures/RA-SSL-Everywhere-deployment-guide.pdf
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com