TLS Support

TLS 1.2 is supported by default.

The TLS version cannot be changed through the CLI. The TLS version is decided based on the server support. For devices that act as an SSL server or HTTPS server, the default connection uses TLS1.2. The system will default to a lower version if necessary.

Use the show ip ssl command to identify the TLS version that is configured on the device.

device# show ip ssl
Session  Protocol Source IP                Source Port  Remote IP                Remote Port  Profile                  
1        TLS1_2   10.177.131.18            32952        10.177.131.216           2083         tls_profile