F5 Sites
  • F5.com
  • LearnF5
  • NGINX
  • MyF5
  • Partner Central
Contact
  • Under Attack?
  • F5 Support
  • DevCentral Support
  • F5 Sales
  • NGINX Sales
  • F5 Professional Services
Skip to contentBrand Logo
Forums
CrowdSRC
Articles
Groups
EventsSuggestionsHow Do I...?
RegisterSign In
  1. DevCentral
  2. Articles
  3. Technical Articles

Cipher Rules And Groups in BIG-IP v13

My mother used to always tell me two things before I left for school in the morning. Be wary of what ciphers your application supports Never use the Default cipher list unless you have compatibi...
Updated Jun 06, 2023
Version 2.0
application delivery
BIG-IP
ciphersuites
dcsecurity17
LTM
security
Chase_Abbott's avatar
Chase_Abbott
Icon for Admin rankAdmin
Joined September 17, 2008
View Profile
dragonflymr's avatar
dragonflymr
Icon for Cirrostratus rankCirrostratus
Jun 07, 2018

Hi,

 

I did the same test (13.1.0.6 on VE) as Chase and no live update :-(

 

Steps:

 

  • Client SSL profile with cache disbaled
  • Group with only f5-ecc assigned
  • Rule with only ECDHE:ECDHE_ECDSA created and assigned to Restrict in group
  • nmap test - TLSv1.0, 1.1 and 1.2 ciphers listed
  • Edited rule with :!TLSv1:!TLSv1_1
  • nmap test - still ciphers for all protocols listed (but when checking in group not TLSv1.0 and 1.1 ciphers present)
  • Edited VS by changing client ssl profile to some other and then back to original
  • nmap test - now only TLSv1.2 cipher listed.

Piotr

 

ABOUT DEVCENTRAL

DevCentral NewsTechnical ForumTechnical ArticlesTechnical CrowdSRCCommunity GuidelinesDevCentral EULAGet a Developer Lab LicenseBecome a DevCentral MVP

RESOURCES

Product DocumentationWhite PapersGlossaryCustomer StoriesWebinarsFree Online CoursesF5 CertificationLearnF5 Training

SUPPORT

Manage SubscriptionsProfessional ServicesProfessional ServicesCreate a Service RequestSoftware DownloadsSupport Portal

PARTNERS

Find a Reseller PartnerTechnology AlliancesBecome an F5 PartnerLogin to Partner Central

F5 logo©2024 F5, Inc. All rights reserved.
TrademarksPoliciesPrivacyCalifornia PrivacyDo Not Sell My Personal Information