For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Nuruddin_Ahmed_'s avatar
Nuruddin_Ahmed_
Icon for Cirrostratus rankCirrostratus
Jun 04, 2016

Proxy SSL - 01260014:3: Cipher c028:5 negotiated is not configured in profile

I am trying to configure proxy ssl for one of the virtual server but it is failing because the negotiated cipher is not supported on F5 -ECDHE-RSA-AES256-SHA384

 

How can i make it work with above cipher? I tried to add above in DEFAULT:ECDHE-RSA-AES256-SHA384 client and server ssl profile but it did not work.

 

4 Replies

  • Hi,

     

    Those ciphers must be removed on the bakend server itself. Changing ciphers on F5 will not help when using Proxy SSL feature.

     

    • Nuruddin_Ahmed_'s avatar
      Nuruddin_Ahmed_
      Icon for Cirrostratus rankCirrostratus
      Hi, i changed to ALL:ECDHE-RSA-AES256-SHA384 and it worked but for other clients its failing for other ciphers. I need to figure out a good cipher which can be hard coded on IIS. Thanks.
  • Hi,

     

    Those ciphers must be removed on the bakend server itself. Changing ciphers on F5 will not help when using Proxy SSL feature.

     

    • Nuruddin_Ahmed_'s avatar
      Nuruddin_Ahmed_
      Icon for Cirrostratus rankCirrostratus
      Hi, i changed to ALL:ECDHE-RSA-AES256-SHA384 and it worked but for other clients its failing for other ciphers. I need to figure out a good cipher which can be hard coded on IIS. Thanks.