CVE-2014-3566: Removing SSLv3 from BIG-IP
The POODLE (CVE-214-03566) vulnerability can force a client to negotiate SSLv3 instead of TLSv1.x ciphers. Then a BEAST-like attack can be conducted against SSLv3 to obtain information from the encry...
Updated Mar 18, 2022
Version 2.0Jeff_Costlow_10
Historic F5 Account
Joined January 26, 2005
Jeff_Costlow_10
Historic F5 Account
Joined January 26, 2005
Neha_51838
Oct 17, 2014Historic F5 Account
Addressing Rishabh's question:
If the "No SSLv3" option is enabled, then the cipher string modification is not required.
Also, to address your point of modifying the base profile: If a base profile is modified in this manner, all profiles inherited from that base profile will take the same affect.
I should also mention that v11.5.0 onwards, SSLv3 is not included in the DEFAULT ciphersuites.