Forum Discussion
need to disable SSLv3 on F5 LTM version 10.2.3 and 11.4.1
Hi, I would like to know if I disable sslv3 in ciphers "DEFAULT:!SSLv3", would it impact our clients in accessing applications/urls.
want to be sure before implementing.
4 Replies
- vj_singh_177738
Nimbostratus
I want to disable sslv3 due to sslv3 vulnerability - LyonsG_85618
Cirrostratus
It WILL stop users/clients that can only use SSLv3 from connecting to your virtual server.
Try looking at ClienTSSL stats to show percentage of SSLv3 connections - it shoudln't be many.
p.s. we applied an iRule that would send a response back to client advising them to upgrade browser.
- vj_singh_177738
Nimbostratus
Thanks for the information.
Like, Google chrome and firefox has already disabled sslv3. IE still allows but there are other option TLS1, 1.1 and 1.2. If we enable tls1,1.1 and 1.2, would it work fine then?
connection can be built with TLS versions as well.
Please correct me if I am wrong here?
- LyonsG_85618
Cirrostratus
Yes if you use something like DEFAULT:!SSLv3 this should block SSLv3 traffic and client should negotiate using TLS
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com