Forum Discussion
SSL/TLS and certificate settings for iquery port
(edited to correct the naming/usage of the port)
Hi!
I need to modify the security settings for the iquery port tcp/4353 (TLS versions, ciphers, SSL certificates and certificate chain on bigip running version 12.1.3.4
Securing the management gui is trivial since in tmsh the 'list /sys httpd' lists all methods...but how is this done for port 4353? We are not (yet) using external iqueries, so it does not matter if the method includes "session breakage" ;-)
- Jason_Nance
Nimbostratus
TCP:4353 is the iQuery port, not the iControl port. The REST API is accessed via TCP:443 of the management interface (just like logging into the web UI) and uses the device certificate for https (the same as the web UI).
- Coleburn_340288
Nimbostratus
Ok, thanks for the clarification! The question however remains...how can I secure tcp/4353 (TLS versions, Certificate and cert-chain, ciphers, etc.)?
- Jason_Nance
Nimbostratus
iQuery also uses your device certificate/key. You manage that in the web UI under "System" -> "Device Certificates" (in 12.x - newer versions of Big IP use "System" -> "Certificate Management" -> "Device Certificate Management").
- Anesh
Cirrostratus
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com