Open Side Menu
Skip to contentBrand Logo
Forums
CrowdSRC
Articles
GroupsEventsSuggestionsHow Do I...?
RegisterSign In
  1. DevCentral
  2. Forums
  3. Technical Forum

Forum Discussion

Lupo_38935's avatar
Lupo_38935
Icon for Nimbostratus rankNimbostratus
16 years ago

mitigating the TLS client-initiated renegotiation MITM attack

I thought I'd share the iRule we use to mitigate one of the recently disclosed TLS attacks. Our focus lies on preventing the possible malicious data insertion during 'client-initiated renegotiation'. ...
application delivery
dev
devops
irules
zoltak_114069's avatar
zoltak_114069
Icon for Nimbostratus rankNimbostratus
15 years ago
9.4.8 HF3 failed as well using the iRule.

 

 

Does anyone have suggestions?

AppWorld Berlin iRules Contest!

DevCentral News
announcement
appworld2026
berlin
event
irules

F5 AppWorld 2026 Las Vegas - iRules Contest Winners!

DevCentral News
announcement
appworld2026
contest
irules

Recent Discussions

  • Changes to DO and AS3 GitHub - no longer monitored
    1 hour ago
    MJ_1024
  • How to Verify config before loading to F5
    4 hours ago
    InquisitiveMai
  • Logical Disk Full to Migrate rSeries
    7 hours ago
    Stan_Marsh
  • HSL - Local TimeZone - in syslog server
    12 hours ago
    PeterSy
  • VIP control across data centers - how to ensure only 1 VIP is up at a time?
    1 day ago
    daboochmeister3
Related Content
  • SSL renegotiation DOS mitigation
    11 years ago
    CodeCentral_194
  • SSL Legacy Renegotiation vs Secure Renegotiation Explained using Wireshark
    7 years ago
    Rodrigo_Albuque
  • F5 Distributed Cloud L7 DoS Attack Mitigation Roundup
    3 months ago
    Dave_Potter
  • How F5 WAF Mitigates 0-Day CVEs - React2Shell Case Study
    4 months ago
    Hen_Golubenko
  • SSL Profiles Part 6: SSL Renegotiation
    12 years ago
    ltwagnon