Forum Discussion
TMcGov_92811
Nimbostratus
Dec 08, 2008iRule to log SSL failures due to weak encryption
I have implemented the following Ciper in an SSL profile per F5 support to prevent SSLv2 or weak encryption schemes from connecting.
ALL:!NULL:!ADH:!LOW:!EXP:RC4+RSA:!SSLv2:+HIGH:+MEDIU...
dennypayne
Employee
Dec 08, 2008If it's getting blocked by the profile, it will never get to the iRule at all. I did a similar rule where the customer wanted to redirect anybody less than 128 bit and not using SSLv3 or TLS to a "Please upgrade your browser" page, and I had to let the profile allow ALL because the iRule won't do anything until the decryption is done.
Denny
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects