config firewall ssl-server
Configure SSL servers.
config firewall ssl-server Description: Configure SSL servers. edit <name> set add-header-x-forwarded-proto [enable|disable] set ip {ipv4-address-any} set mapped-port {integer} set port {integer} set ssl-algorithm [high|medium|...] set ssl-cert {string} set ssl-client-renegotiation [allow|deny|...] set ssl-dh-bits [768|1024|...] set ssl-max-version [tls-1.0|tls-1.1|...] set ssl-min-version [tls-1.0|tls-1.1|...] set ssl-mode [half|full] set ssl-send-empty-frags [enable|disable] set url-rewrite [enable|disable] next end
config firewall ssl-server
Parameter |
Description |
Type |
Size |
|||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
add-header-x-forwarded-proto |
Enable/disable adding an X-Forwarded-Proto header to forwarded requests. |
option |
- |
|||||||||||
|
|
|||||||||||||
ip |
IPv4 address of the SSL server. |
ipv4-address-any |
Not Specified |
|||||||||||
mapped-port |
Mapped server service port. |
integer |
Minimum value: 1 Maximum value: 65535 |
|||||||||||
name |
Server name. |
string |
Maximum length: 35 |
|||||||||||
port |
Server service port. |
integer |
Minimum value: 1 Maximum value: 65535 |
|||||||||||
ssl-algorithm |
Relative strength of encryption algorithms accepted in negotiation. |
option |
- |
|||||||||||
|
|
|||||||||||||
ssl-cert |
Name of certificate for SSL connections to this server. |
string |
Maximum length: 35 |
|||||||||||
ssl-client-renegotiation |
Allow or block client renegotiation by server. |
option |
- |
|||||||||||
|
|
|||||||||||||
ssl-dh-bits |
Bit-size of Diffie-Hellman. |
option |
- |
|||||||||||
|
|
|||||||||||||
ssl-max-version |
Highest SSL/TLS version to negotiate. |
option |
- |
|||||||||||
|
|
|||||||||||||
ssl-min-version |
Lowest SSL/TLS version to negotiate. |
option |
- |
|||||||||||
|
|
|||||||||||||
ssl-mode |
SSL/TLS mode for encryption and decryption of traffic. |
option |
- |
|||||||||||
|
|
|||||||||||||
ssl-send-empty-frags |
Enable/disable sending empty fragments to avoid attack on CBC IV. |
option |
- |
|||||||||||
|
|
|||||||||||||
url-rewrite |
Enable/disable rewriting the URL. |
option |
- |
|||||||||||
|
|