Forum Discussion
nathe
Cirrocumulus
Nov 17, 2009SSL redirect iRule
Afternoon,
We have a Big-IP ASM appliance (v9.4.4) in front of our Corporate internet site. We need to restrict customers from connecting with less than 128 bit encryption and hope to r...
hoolio
Cirrostratus
Nov 17, 2009Hi Nathan,
With the client SSL profile set to not allow the 128bit cipher, LTM will send a reset to a client who attempts to use a 128 bit cipher. This will happen regardless of whether the iRule is enabled or not.
The iRule is a better option as it tells the client that there is a problem and how to fix it. The only downside to the iRule option is that vulnerability scans will show a false positive for weak ciphers. It's safe to ignore this as no client with a weak cipher will be able to get past LTM.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects