Configure secure TLS ciphers on F5 BIG-IP SSL profiles
More actions
Configure and validate TLS cipher selection for F5 BIG-IP Client SSL and Server SSL profiles.
Recommended approach
F5 documentation states that the DEFAULT cipher string is appropriate in most cases. Where an environment requires explicit security, compliance or interoperability controls, BIG-IP supports custom cipher strings as well as cipher rules and cipher groups.
For newer BIG-IP releases, cipher groups are generally easier to govern than maintaining a long static cipher string because they can express allowed/restricted cipher rules and associated cryptographic parameters.
Protocol versions
TLS protocol versions and cipher selection are related but separate controls. The IETF has formally deprecated TLS 1.0 and TLS 1.1. New deployments should normally use TLS 1.2 or later unless a documented interoperability requirement requires an exception.
BIG-IP protocol availability and defaults vary by release and profile, so verify the configuration on the target system before making changes.
Inspect available ciphers
Use the BIG-IP TMSH utility to display the Client SSL ciphers matched by a cipher string.
tmsh run util clientssl-ciphers DEFAULT
Replace DEFAULT with the cipher string you want to evaluate when reviewing a proposed configuration.
Configure a Client SSL or Server SSL profile
In the BIG-IP Configuration utility:
- Open Local Traffic → Profiles → SSL.
- Select Client or Server as appropriate.
- Open an existing profile or create a new custom profile.
- Set the profile configuration to Advanced where required.
- In Ciphers, select either a cipher group or a cipher string.
- Apply the reviewed configuration.
- Test TLS negotiation with the clients or servers that the profile must support before production rollout.
Cipher rules and cipher groups
BIG-IP supports cipher rules that define suites and related cryptographic parameters. Rules can then be combined into a cipher group.
A typical workflow is:
- Open Local Traffic → Ciphers → Rules and create or review the required rule.
- Open Local Traffic → Ciphers → Groups.
- Add the required rules to the allowed, restricted or excluded lists.
- Review the resulting cipher group.
- Assign the cipher group to the relevant Client SSL or Server SSL profile.
- Test the resulting profile before deployment.
Operational checks
Before changing an existing production SSL profile:
- Record the current profile configuration.
- Confirm which virtual servers use the profile.
- Identify required client and server interoperability.
- Test the proposed configuration before broad rollout.
- Confirm TLS negotiation and application functionality after the change.
- Retain a rollback path to the previous profile settings.