Forum Discussion
Irule for restricting selected ips for NOT USING TLSV1 and 1.1
- Jun 27, 2018
matchclass ...
Note: matchclass has been deprecated in v10 in favor of the new commands. The class command offers better functionality and performance than matchclass.
Inserting the appropriate class command into this iRule would look something like this:
when CLIENT_ACCEPTED { if { [class match [IP::client_addr] equals TLSV1.0_1.1_Enable ]} { SSL::profile example_profile_enable_weak_TLS } else { SSL::profile example_profile_disable_weak_TLS } }
matchclass ...
Note: matchclass has been deprecated in v10 in favor of the new commands. The class command offers better functionality and performance than matchclass.
Inserting the appropriate class command into this iRule would look something like this:
when CLIENT_ACCEPTED {
if { [class match [IP::client_addr] equals TLSV1.0_1.1_Enable ]} {
SSL::profile example_profile_enable_weak_TLS
} else {
SSL::profile example_profile_disable_weak_TLS
}
}
- vvskaladhar_488Jun 28, 2018
Nimbostratus
thank you so much
this worked.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com