TLS implementation in FastIron devices

By default, all TLS versions are supported on devices that act as an HTTPS server.

For devices that act as an SSL server or HTTPS server, the default connection is with TLS1.2. For devices that acts as an SSL client or syslog, OpenFlow, or secure AAA client, during session negotiation, the TLS version is decided based on the server support.

You can configure the minimum TLS version on FastIrondevices using the ip ssl min-version{ tls_1_1 | tls_1_2 } command.

The following example configures TLS 1.2.

device(config)# ip ssl min-version 
  tls_1_1   TLS Version 1.1 
  tls_1_2   TLS Version 1.2
device(config)# ip ssl min-version tls_1_2

Use the show ip ssl command to identify the TLS version that is configured on the device.

device(config)# show ip ssl
Session Protocol  Source IP      Source Port  Remote IP     Remote Port
1       TLS_1_2   10.20.157.102  634          10.25.105.201 60892