424
Step Command
Remarks
ecdhe_rsa_aes_128_gcm
_sha256
|
ecdhe_rsa_aes_256_cbc_
sha384
|
ecdhe_rsa_aes_256_gcm
_sha384
|
rsa_aes_128_cbc_sha
|
rsa_aes_128_cbc_sha256
|
rsa_aes_256_cbc_sha
|
rsa_aes_256_cbc_sha256
}
6.
Specify the SSL protocol
version for the SSL client
policy.
•
In non-FIPS mode:
version
{
ssl3.0
|
tls1.0
|
tls1.1
|
tls1.2
}
•
In FIPS mode:
version
{
tls1.0
|
tls1.1
|
tls1.2
}
By default, an SSL client policy
uses TLS 1.0.
To ensure security, do not
specify SSL 3.0 for an SSL client
policy.
7.
Enable the SSL client to
authenticate servers through
digital certificates.
server-verify enable
By default, SSL server
authentication is enabled.
Displaying and maintaining SSL
Execute
display
commands in any view.
Task Command
Display cryptographic library version information.
display crypto version
Display SSL server policy information.
display ssl server-policy
[
policy-name
]
Display SSL client policy information.
display ssl client-policy
[
policy-name
]
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...