Forum Discussion

yuanqiang_22112's avatar
yuanqiang_22112
Icon for Nimbostratus rankNimbostratus
Dec 23, 2016

perfect forward secrecy cipher

BIG-IP LTM2000 V11.4.1 , I want to use pfs cipher and tls1.2 for ssl offloading ; 11.4.1 supported Perfect Forward Secrecy ? how to configured PFS cipher.

 

1 Reply

  • 11.4.1 supports TLS1.2 and ECDHE and hence, supports PFS.

     

    - this has information on cipher suites supported by different F5 code versions.

     

    PFS is provided by DHE/ECDHE.

     

    In order to check if your code version supports DHE/ECDHE, check output from tmm --clientciphers DEFAULT