Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Configure secure TLS ciphers on F5 BIG-IP SSL profiles

From Tech-Wiki


Configure and validate TLS cipher selection for F5 BIG-IP Client SSL and Server SSL profiles.

ⓘ
Validation status
This article was reviewed against current F5 BIG-IP SSL Administration documentation for BIG-IP 17.5.1 and 21.1.0, together with IETF RFC 8996, on 27 September 2026. It provides configuration guidance rather than a site-specific cipher policy.
!
Do not reuse static legacy cipher lists blindly
Supported protocol versions, cipher suites, signature algorithms and key-exchange options vary by BIG-IP release, platform and SSL profile. Validate any custom policy on the target BIG-IP release and with required client/server peers before production use.

F5 documentation states that the DEFAULT cipher string is appropriate in most cases. Where an environment requires explicit security, compliance or interoperability controls, BIG-IP supports custom cipher strings as well as cipher rules and cipher groups.

For newer BIG-IP releases, cipher groups are generally easier to govern than maintaining a long static cipher string because they can express allowed/restricted cipher rules and associated cryptographic parameters.

✓
Prefer policy over copied cipher lists
Start with the BIG-IP defaults unless there is a documented requirement to change them. Where explicit control is required, define and test a cipher group or a carefully reviewed cipher string rather than copying an old list from another appliance or software release.

Protocol versions

TLS protocol versions and cipher selection are related but separate controls. The IETF has formally deprecated TLS 1.0 and TLS 1.1. New deployments should normally use TLS 1.2 or later unless a documented interoperability requirement requires an exception.

BIG-IP protocol availability and defaults vary by release and profile, so verify the configuration on the target system before making changes.

Inspect available ciphers

Use the BIG-IP TMSH utility to display the Client SSL ciphers matched by a cipher string.

>_Display ciphers matched by DEFAULT
tmsh run util clientssl-ciphers DEFAULT

Replace DEFAULT with the cipher string you want to evaluate when reviewing a proposed configuration.

Configure a Client SSL or Server SSL profile

In the BIG-IP Configuration utility:

  1. Open Local Traffic → Profiles → SSL.
  2. Select Client or Server as appropriate.
  3. Open an existing profile or create a new custom profile.
  4. Set the profile configuration to Advanced where required.
  5. In Ciphers, select either a cipher group or a cipher string.
  6. Apply the reviewed configuration.
  7. Test TLS negotiation with the clients or servers that the profile must support before production rollout.
ⓘ
ECDSA certificate chains
F5 documentation notes that when an ECDSA certificate key chain is used, the configured cipher policy must include ECDSA-compatible cipher suites. Validate certificate type and cipher policy together.

Cipher rules and cipher groups

BIG-IP supports cipher rules that define suites and related cryptographic parameters. Rules can then be combined into a cipher group.

A typical workflow is:

  1. Open Local Traffic → Ciphers → Rules and create or review the required rule.
  2. Open Local Traffic → Ciphers → Groups.
  3. Add the required rules to the allowed, restricted or excluded lists.
  4. Review the resulting cipher group.
  5. Assign the cipher group to the relevant Client SSL or Server SSL profile.
  6. Test the resulting profile before deployment.

Operational checks

Before changing an existing production SSL profile:

  • Record the current profile configuration.
  • Confirm which virtual servers use the profile.
  • Identify required client and server interoperability.
  • Test the proposed configuration before broad rollout.
  • Confirm TLS negotiation and application functionality after the change.
  • Retain a rollback path to the previous profile settings.

Official references

See also