Forum Discussion
Amit585731
Mar 21, 2016Nimbostratus
Regarding cipher negotiation for LTM
Hi,
Needed suggestion regarding cipher negotiation between LTM and server. As per my understanding when client sends hello it sends all cipher value supported. So in case of serverssl profile I ...
Hannes_Rapp
Mar 26, 2016Nimbostratus
A Reset (TCP) from end-server is not a correct SSL/TLS downgrade response. Probably you're using Window Server 2008?
You can mitigate by enforcing the use of TLSv1.0 on your BigIP serverssl profile. Do not modify the default serverssl profile, but create a new one with your custom settings. When done, apply that custom tlsv1.0-only serverssl profile to your Virtual Server.
Creating a custom TLSv1.0-only serverssl profile (Local Traffic - Profiles - SSL - Server)
1) Create a new serverssl profile
2) Name it as you like, i.e.profile_serverssl_TLSv1-0
3) Parent Profile - serverssl
4) Expand the configuration section - advanced
5) In Cipher configuration, replace DEFAULT
keyword with TLSv1
6) Keep the rest as default, unless you have other requirementsRecent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects