12-50
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 12 Configuring Traffic Policies
Configuring Rules and Actions for Policy Maps
SSL Defines load balancing decisions based on the specific SSL cipher or cipher strength.
Note The SSL option is not available with the ACE NPE software version (see the “Information
About the ACE No Payload Encryption Software Version” section on page 1-2).
Enables the ACE to load balance client traffic to different server farms based on the SSL
encryption level negotiated with the ACE during SSL termination.
If you select this method:
1. In the SSL Cipher Match Type field, select the match type. Options include:
–
Equal To—Specifies an SSL cipher for the load balancing decision.
–
Less Than—Specifies SSL cipher strength for the load balancing decision.
2. If you selected Equal To, in the Cipher Name field specify an SSL cipher for the load
balancing decision. The possible values are as follows:
–
RSA_EXPORT1024_WITH_DES_CBC_SHA
–
RSA_EXPORT1024_WITH_RC4_56_MD5
–
RSA_EXPORT1024_WITH_RC4_56_SHA
–
RSA_EXPORT_WITH_DES40_CBC_SHA
–
RSA_EXPORT_WITH_RC4_40_MD5
–
RSA_WITH_3DES_EDE_CBC_SHA
–
RSA_WITH_AES_128_CBC_SHA
–
RSA_WITH_AES_256_CBC_SHA
–
RSA_WITH_DES_CBC_SHA
–
RSA_WITH_RC4_128_MD5
–
RSA_WITH_RC4_128_SHA
3. If you selected Less Than, in the Specify Minimum Cipher Strength field specify a
non-inclusive minimum SSL cipher bit strength. For example, if you specify a cipher strength
value of 128, any SSL cipher that was no greater than 128 would hit the traffic policy. If the
SSL cipher was 128-bit or greater, the connection would miss the policy.
The possible values are as follows:
–
56—56-bit strength
–
128—128-bit strength
–
168—168-bit strength
–
256—256-bit strength
Table 12-19 Policy Match Condition Types (continued)
Match Condition Description
Comments to this Manuals