TLS implementation in FastIron devices
By default, all TLS versions are supported on devices that act as an HTTPS server.
For devices that act as an SSL server or HTTPS server, the default connection is with TLS1.2. For devices that acts as an SSL client or syslog, OpenFlow, or secure AAA client, during session negotiation, the TLS version is decided based on the server support.
You can configure the minimum TLS version on
FastIrondevices using the
ip ssl min-version{
tls_1_1
|
tls_1_2
} command.
The following example configures TLS 1.2.
device(config)# ip ssl min-version tls_1_1 TLS Version 1.1 tls_1_2 TLS Version 1.2 device(config)# ip ssl min-version tls_1_2
Use the
show ip ssl command to identify the TLS version that is configured on the device.
device(config)# show ip ssl Session Protocol Source IP Source Port Remote IP Remote Port 1 TLS_1_2 10.20.157.102 634 10.25.105.201 60892