Working with Clusters and Match Rules
Configuring SSE Using the GUI
1. Log in to the GUI.
Global Cipher Suite and TLS Configuration
First, you will need to enable SSE on your Equalizer on a global level.
2. Select
System > Global > Server Side Encryption
on the left navigational pane.The following will be
displayed on the right configuration pane.
3. Enter the cipher suite (set of cipher specifications) to use in the encryption in the
Cipher
Suites
box. A default cipher suite is used by default (AES128-SHA:DES-CBC3-SHA:RC4-
SHA:RC4-MD5:AES256-SHA:!SSLv2).
Note
- SSLv2 is not supported as Equalizer will not negotiate with packets using SSLv2 encyrption.
4. Add additional
Cipher Suites
as described in
"Layer 7 SSL Security (HTTPS Clusters)"
as necessary.
5. Enable each TLS version that you wish to use. For example, if you select only
Allow TLSv1.1
,
this will be the only allowable TLS version used with the
Cipher Suite
. Select
Allow TLSv1.0
and/or
Allow TLSv1.2
as needed. At least one encryption type must be selected.
6. Click on
Commit
to save your settings.
360
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......