Forum Discussion
SSLv3, TLS1.0 and cipherstrings...
Without seeing the Wireshark capture, it's hard to say exactly what's going on, but it could be something like this:
http-8443-14, READ: SSLv3 Handshake, length = 87 *** ClientHello, TLSv1
In this case, there is a record of type "Handshake Message" version SSLv3 and length 87 bytes (a typical record size). The contents of the Handshake Message show that this is a "Client Hello" and the client supports up to TLSv1.0.
It's possible that the BIG-IP sees the initial "SSLv3" part of the Handshake Message and rejects it based on the configuration of the SSL profile.
Here's some more info that might help: https://support.f5.com/csp/article/K15292
Also, for troubleshooting purposes, it might help to change the SSL logging level to "debug" so you can see exactly why the BIG-IP sent the handshake failure alert.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com