For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

justin_westover's avatar
justin_westover
Icon for Nimbostratus rankNimbostratus
Aug 24, 2016

Log SSL Handshake failures through HSL to Splunk

We host several web services sites and our clients typically connect to us using an automated program. Those programs are generally hard coded to support a specific TLS cipher version. We recently went through and disabled TLSv1.0 under our SSL profile and we're finding that some clients can no longer connect, they're receiving a reset from us. We have high speed logging enabled along with an iRule attached to the VS that sends traffic to our Splunk server. This works well for stuff that isn't being denied before the iRule is processed. In our case, it would seem that some of our clients are connecting with TLSv1.0 and they don't support additional versions so the SSL handshake fails so the F5 denies the traffic and sends a reset to the client. Due to this behavior, our iRule never sees the traffic so it can't report on it. I'm looking for a way to report on these logs and send them into Splunk. Anyone have any ideas? Thanks

 

1 Reply

  • JG's avatar
    JG
    Icon for Cumulonimbus rankCumulonimbus

    I hope the answers to this posting will be of help to you: https://devcentral.f5.com/questions/irule-to-log-ssl-cipher-version .