3.146. SSLSettings

Description

Settings related to SSL (Secure Sockets Layer). Subsystems affected: RemoteMgmtHTTPS, SSLVPN (tunnels and portal page), TLS ALG, UserAuth, and LW-HTTPS ALG block pages.

Properties

TLS_AES_128_GCM_SHA256
Enable TLS v1.3 cipher TLS_AES_128_GCM_SHA256. (Default: Yes)
TLS_AES_256_GCM_SHA384
Enable TLS v1.3 cipher TLS_AES_256_GCM_SHA384. (Default: Yes)
TLS_CHACHA20_POLY1305_SHA256
Enable TLS v1.3 cipher TLS_CHACHA20_POLY1305_SHA256. (Default: Yes)
TLS_ECDHE_ECDSA_AES_128_GCM_SHA256
Enable TLS v1.2 cipher TLS_ECDHE_ECDSA_AES_128_GCM_SHA256. (Default: Yes)
TLS_ECDHE_RSA_AES_128_GCM_SHA256
Enable TLS v1.2 cipher TLS_ECDHE_RSA_AES_128_GCM_SHA256. (Default: Yes)
TLS_ECDHE_ECDSA_AES_256_GCM_SHA384
Enable TLS v1.2 cipher TLS_ECDHE_ECDSA_AES_256_GCM_SHA384. (Default: Yes)
TLS_ECDHE_RSA_AES_256_GCM_SHA384
Enable TLS v1.2 cipher TLS_ECDHE_RSA_AES_256_GCM_SHA384. (Default: Yes)
TLS_ECDHE_ECDSA_CHACHA20_POLY1305_SHA256
Enable TLS v1.2 cipher TLS_ECDHE_ECDSA_CHACHA20_POLY1305_SHA256. (Default: Yes)
TLS_ECDHE_RSA_CHACHA20_POLY1305_SHA256
Enable TLS v1.2 cipher TLS_ECDHE_RSA_CHACHA20_POLY1305_SHA256. (Default: Yes)
TLS_DHE_RSA_AES_128_GCM_SHA256
Enable TLS v1.2 cipher TLS_DHE_RSA_AES_128_GCM_SHA256. (Default: Yes)
TLS_DHE_RSA_AES_256_GCM_SHA384
Enable TLS v1.2 cipher TLS_DHE_RSA_AES_256_GCM_SHA384. (Default: Yes)
TLS_DHE_RSA_CHACHA20_POLY1305_SHA256
Enable TLS v1.2 cipher TLS_DHE_RSA_CHACHA20_POLY1305_SHA256. (Default: No)
TLS_ECDHE_ECDSA_AES_128_CBC_SHA256
Enable TLS v1.2 cipher TLS_ECDHE_ECDSA_AES_128_CBC_SHA256. (Default: No)
TLS_ECDHE_RSA_AES_128_CBC_SHA256
Enable TLS v1.2 cipher TLS_ECDHE_RSA_AES_128_CBC_SHA256. (Default: No)
TLS_ECDHE_ECDSA_AES_256_CBC_SHA384
Enable TLS v1.2 cipher TLS_ECDHE_ECDSA_AES_256_CBC_SHA384. (Default: No)
TLS_ECDHE_RSA_AES_256_CBC_SHA384
Enable TLS v1.2 cipher TLS_ECDHE_RSA_AES_256_CBC_SHA384. (Default: No)
TLS_DHE_RSA_AES_128_CBC_SHA256
Enable TLS v1.2 cipher TLS_DHE_RSA_AES_128_CBC_SHA256. (Default: No)
TLS_DHE_RSA_AES_256_CBC_SHA256
Enable TLS v1.2 cipher TLS_DHE_RSA_AES_256_CBC_SHA256. (Default: No)
TLS_RSA_AES_128_GCM_SHA256
Enable TLS v1.2 cipher TLS_RSA_AES_128_GCM_SHA256. (Default: No)
TLS_RSA_AES_256_GCM_SHA384
Enable TLS v1.2 cipher TLS_RSA_AES_256_GCM_SHA384. (Default: No)
TLS_RSA_AES_128_CBC_SHA256
Enable TLS v1.2 cipher TLS_RSA_AES_128_CBC_SHA256. (Default: No)
TLS_RSA_AES_256_CBC_SHA256
Enable TLS v1.2 cipher TLS_RSA_AES_256_CBC_SHA256. (Default: No)
TLS_ECDHE_ECDSA_AES_128_CBC_SHA
Enable TLS v1.0 cipher TLS_ECDHE_ECDSA_AES_128_CBC_SHA. (Default: No)
TLS_ECDHE_RSA_AES_128_CBC_SHA
Enable TLS v1.0 cipher TLS_ECDHE_RSA_AES_128_CBC_SHA. (Default: No)
TLS_ECDHE_ECDSA_AES_256_CBC_SHA
Enable TLS v1.0 cipher TLS_ECDHE_ECDSA_AES_256_CBC_SHA. (Default: No)
TLS_ECDHE_RSA_AES_256_CBC_SHA
Enable TLS v1.0 cipher TLS_ECDHE_RSA_AES_256_CBC_SHA. (Default: No)
TLS_RSA_AES_128_CBC_SHA
Enable TLS v1.0 cipher TLS_RSA_AES_128_CBC_SHA. (Default: No)
TLS_RSA_AES_256_CBC_SHA
Enable TLS v1.0 cipher TLS_RSA_AES_256_CBC_SHA. (Default: No)
SSL_RSA_3DES_EDE_CBC_SHA
Enable TLS v1.0 cipher SSL_RSA_3DES_EDE_CBC_SHA. (Default: No)
[Note] Note
This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type.