Layer 7 SSL Security (HTTPS Clusters)
Layer 7 Security allows you to configure various options that are specific to HTTPS connections.
Parameters
The table below shows the parameters and values used in the configuration of HTTPS cluster
security.
GUI Parameter (CLI Parameter)
Description
Cipher Suites
(
cipherspec
)
Lists the supported cipher suites for incoming HTTPS requests. If a client
request comes into Equalizer that does not use a cipher in this list, the
connection is refused.
Equalizer supports DHE-RSA, DHE-DSS, ECDHE-RSA, and ECDHE-ECDSA
cipher suites.
Flags
Allow SSLv2
(
allow_sslv2
)
Enables SSLv2 for client connections.
Allow SSLv3
(
allow_sslv3
)
Enables SSLv3 for client connections. This option is enabled by default.
Software SSL Only
(
software_ssl_only
)
(not applicable on E250GX)
This flag appears only on systems that are equipped with Hardware SSL
Acceleration. When enabled, it specifies that all SSL operations will be
performed in software, instead of being performed using the SSL accelerator
hardware. This flag does not appear on systems that are not equipped with
Hardware SSL Acceleration, since on these units SSL operations are always
performed in software. This flag is disabled by default.
All units with Hardware SSL Acceleration can process the TLSv1.0, TLSv1.1,
and TLSv1.2 protocols in both hardware and software, except for legacy GX
hardware. On legacy GX hardware, only TLSv1.0 is supported by Hardware
SSL Acceleration; if you want to enable TLSv1.1 or TLSv1.2 on GX hardware,
you must first enable this flag.
Please note that enabling this option will reduce the processor and memory
resources generally available for processing cluster traffic, since performing
SSL operations in software requires use of the system CPU and system
memory (instead of the dedicated SSL acceleration hardware CPU and
memory).
Allow TLS 1.0
(
allow_tls10
)
This option enables and disables support for the TLSv1.0 protocol. Enabled
by default. If multiple TLS versions are enabled, the first supported TLS
version negotiated by a client will be used.
Allow TLS 1.1
(
allow_tls11
)
This option enables and disables support for the TLSv1.1 protocol. Disabled
by default. If multiple TLS versions are enabled, the first supported TLS
version negotiated by a client will be used.
Allow TLS 1.2
(
allow_tls12
)
This option enables and disables support for the TLSv1.2 protocol. Disabled
by default. If multiple TLS versions are enabled, the first supported TLS
version negotiated by a client will be used.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
349
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......