
235
Step Command
Remarks
2.
(Optional.) Disable specific
SSL protocol versions on the
device.
•
In non-FIPS mode:
ssl version
{
ssl3.0
|
tls1.0
|
tls1.1
} *
disable
•
In FIPS mode:
ssl version
{
tls1.0
|
tls1.1
} *
disable
By default:
•
In non-FIPS mode, the
device supports SSL 3.0,
TLS 1.0, TLS 1.1, and
TLS 1.2.
•
In FIPS mode, the device
supports TLS 1.0, TLS
1.1, and TLS 1.2.
3.
(Optional.) Disable SSL
session renegotiation.
ssl renegotiation disable
By default, SSL session
renegotiation is enabled.
4.
Create an SSL server policy
and enter its view.
ssl server-policy
policy-name
By default, no SSL server
policies exist on the device.
5.
(Optional.) Specify a PKI
domain for the SSL server
policy.
pki-domain
domain-name
By default, no PKI domain is
specified for an SSL server
policy.
If SSL server authentication is
required, you must specify a
PKI domain and request a
local certificate for the SSL
server in the domain.
For information about how to
create and configure a PKI
domain, see "
Содержание 10500 series
Страница 326: ...312 No duration limit for this SA ...