Forum Discussion

vj_singh_177738's avatar
vj_singh_177738
Icon for Nimbostratus rankNimbostratus
Dec 09, 2014

need to disable SSLv3 on F5 LTM version 10.2.3 and 11.4.1

Hi, I would like to know if I disable sslv3 in ciphers "DEFAULT:!SSLv3", would it impact our clients in accessing applications/urls.

 

want to be sure before implementing.

 

4 Replies

  • It WILL stop users/clients that can only use SSLv3 from connecting to your virtual server.

     

    Try looking at ClienTSSL stats to show percentage of SSLv3 connections - it shoudln't be many.

     

    p.s. we applied an iRule that would send a response back to client advising them to upgrade browser.

     

  • Thanks for the information.

     

    Like, Google chrome and firefox has already disabled sslv3. IE still allows but there are other option TLS1, 1.1 and 1.2. If we enable tls1,1.1 and 1.2, would it work fine then?

     

    connection can be built with TLS versions as well.

     

    Please correct me if I am wrong here?

     

    • LyonsG_85618's avatar
      LyonsG_85618
      Icon for Cirrostratus rankCirrostratus
      Yes if you use something like DEFAULT:!SSLv3 this should block SSLv3 traffic and client should negotiate using TLS