Forum Discussion
Nuttycomputer_1
Nimbostratus
Oct 16, 2014iRule - Reject SSL 3.0
Looking for assistance on whether this is possible with an iRule.
We have a vendor system behind an F5 and with the new SSL 3.0 the vendor has gotten back to us indicating they have no plans to ...
Nuttycomputer_1
Nimbostratus
Oct 16, 2014Default would be to just drop the packet... I'm thinking something like this is simple enough. Haven't touched iRules since a brief LTM training so I can't recall if I need to add a forward to pool or if the drop statement is enough:
when HTTP_REQUEST {
Check Encryption type
if { [SSL::cipher version] = SSLv3 }{
If SSLv3 Detected drop connection
drop
}
}
jgranieri_42214
Nimbostratus
Oct 16, 2014drop or reject
Rule 1 on VS1
when HTTP_REQUEST priority 100 {
This event in this iRule runs first
reject
log local0. "Rejecting this request"
}
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects