Manual

Table Of Contents
Software User Guide 103
Services Tab
EnableSSL:SelectYestoconfigureSSLclient/server.SelectNoandthentheApplybuttontodisableSSL.
SelectActivityLogLevel:ThisoptioncontrolsthelogginglevelforSSLConnectionactivity.Therecommendedsetting
foraproductionenvironmentis:Summary.Foratestenvironment:Full.
WaitforConnection(sec.):Time(in
seconds)allowedaftersendingSYNpackets,towaitforSYNACK.Therecom
mendedsettingforthisfieldis20seconds.
IdleTimeout(min):Time(inminutes)allowedfornotrafficoveranSSLconnection,beforeclosingdownthelink.The
recommendedsettingforthisfieldis720(minutes).
EnableAdvance
Setup:SelectYestomodifyadvancedSSLoptions.
BindInterfaceforacceptingTCPConnections:Thiswillrestricttheunencryptedlisteningsockettoallowconnections
comingintothespecifiedinterfaceonly.TherecommendedsettingforthisfieldisAny.
BindInterfaceforoutgoingSSLConnections:Thiswillrestricttheencryptedsocketto
initiateconnectionsoutthe
specifiedinterfaceonly.Specifyinganinterfaceheremayconflictwithpolicyrouting,howeveritmayberequiredina
GRE/VPNorothertunneledenvironment.Pleaseconsultwithanetworkarchitectforadditionalassistance.Therec
ommendedsettingforthisfieldisAny.
Ciphers:Thisfieldisa
listofsupportedopensslciphers.Pleaseconsultsupportstaffbeforeattemptingtochange
thesevalues.ReferenceGoogle:opensslcipherlistformoreinformation.Therecommendedsettingforthisfieldis:
RC4MD5:RC5SHA:SSLv3
SelectCertificate:Specifyingacertificateinclientmodewillusethiscertificatechainasaclientsidecertificate
chain.
Usingclientsidecertsisoptional.ThecertificatesmustbeinPEMformat,withanunencryptedkey(notpasswordpro
tectedwhengenerated).UseAdmin>CertificateManagertoinstall/updatecerts.
SelectKeepAlivebehavior:ThisoptionenablesTCPKeepalivesontheunderlyingsockets.Thefollowingoptionsare
supported: