Manual

Table Of Contents
Software User Guide 106
Services Tab
EnableSSL:SelectYestoconfigureSSLclient/server.SelectNoandclicktheApplybuttontodisableSSL.
SelectActivityLogLevel:Thiscontrolsthelog ginglevelforSSLConnectionactivity.Therecommendedsettingfora
productionenvironmentisSummary.TherecommendedsettingforatestenvironmentisFull.
Waitfor
Connection(sec.):Time(inseconds)allowedaftersendingSYNpackets,towaitforSYNACK.Therecom
mendedsettingforthisfieldis20seconds.
IdleTimeout(min.):Time(inminutes)allowedfornotrafficoveranSSLconnection,beforeclosingdownthelink.The
recommendedsettingis720minutes.
Select
Certificate:Aservercertificatemustbeprovided.Thiswillbeusedtoencryptcommunicationwithallclients.
ThecertificatesmustbeinPEMformat,withanunencryptedkey(notpasswordprotectedwhengenerated).Self
signedcertificatesarehighlyrecommended.UseAdmin>CertificateManagertoinstall/updatecerts.
EnableAdvancedSetup:SelectYes
tomodifyadvancedSSLoptions.
BindInterfaceforacceptingSSLConnections:Thiswillrestricttheencryptedlisteningsockettoallowconnections
comingintothespecifiedinterfaceonly.TherecommendedsettingforthisfieldisAny.
BindInterfaceforoutgoingTCPConnections:Thiswillrestricttheunencryptedsockettoinitiateconnectionsout
the
specifiedinterfaceonly.Specifyinganinterfaceheremayconflictwithpolicyrouting,howeveritmayberequiredina
GRE/VPNorothertunneledenvironment.Pleaseconsultwithanetworkarchitectforadditionalassistance.Therec
ommendedsettingforthisfieldisAny.
Ciphers:Thisfieldisalistofopenssl
cipherssupported.Pleaseconsultsupportstaffbeforeattemptingtochange.Ref
erenceGoogle:”opensslcipherlistformoreinformation.Therecommendedsettingsforthisfieldare:RC4MD5:RC4
SHA:SSLv3.
SelectKeepAlivebehavior:ThisoptionenablesTCPKeepalivesontheunderlyingsockets.Thefollowingoptionsare
supported:
SelectKeepAlive
behavior:ThisoptionenablesTCPKeepalivesontheunderlyingsockets.Thefollowingoptionsare
supported:
•None:Keepalivesnotused.
All:Keepalivesenabledforallsockets.
Accept:Keepalivesenabledforlisteningserversocketside connectionsonly.Thisappliestothecleartextser verforCli
entmodesockets,ortheSSLEncryptedserverforServermodesockets.
•Remote:Keepalivesenabledforclientinitiatedsockets.
•Local:
KeepalivesenabledforClientconnectionsboundtoalocalIPaddress.
YoumayneedtoadjustthemasterKeepalivetimer viaNetwork>TCPGlobalSettings>TCPKeepAlives.
Note:EnablingTCPkeepalivesmaydramaticallyincreasethetotalamountoftrafficfortheaffectedsocket(s)depend
ingonthemasterinterval,probeandtimeoutsettings,whichshouldbeconsideredforconnections
usingawireless
(cellular)connectionwithrespecttototaldatausageforthesubscriptedplan.
SSLServerTableProperties: