When you add HTTPS listeners, you can select desired security policies to improve service security. A security policy is a combination of TLS protocols and cipher suites.
and select the desired region and project.
in the upper left corner to display Service List and choose Network > Elastic Load Balancing.Parameter |
Description |
TLS Version |
Cipher Suite |
|---|---|---|---|
TLS-1-0 |
TLS 1.0, TLS 1.1, and TLS 1.2 and supported cipher suites (high compatibility and moderate security) |
TLS 1.2 TLS 1.1 TLS 1.0 |
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES128-SHA256:AES256-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:AES128-SHA:AES256-SHA |
TLS-1-1 |
TLS 1.1 and TLS 1.2 and supported cipher suites (moderate compatibility and moderate security) |
TLS 1.2 TLS 1.1 |
|
TLS-1-2 |
TLS 1.2 and supported cipher suites (moderate compatibility and high security) |
TLS 1.2 |
|
TLS-1-2-Strict |
Strict TLS 1.2 and supported cipher suites (low compatibility and ultra-high security) |
TLS 1.2 |
ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES128-SHA256:AES256-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384 |
Security Policy |
TLS-1-0 |
TLS-1-1 |
TLS-1-2 |
TLS-1-2-Strict |
TLS-1-2-FS |
|---|---|---|---|---|---|
TLS versions |
|||||
Protocol-TLS 1.3 |
- |
- |
- |
- |
√ |
Protocol-TLS 1.2 |
√ |
√ |
√ |
√ |
√ |
Protocol-TLS 1.1 |
√ |
√ |
- |
- |
- |
Protocol-TLS 1.0 |
√ |
- |
- |
- |
- |
Cipher suites |
|||||
EDHE-RSA-AES128-GCM-SHA256 |
√ |
√ |
√ |
√ |
- |
ECDHE-RSA-AES256-GCM-SHA384 |
√ |
√ |
√ |
√ |
√ |
ECDHE-RSA-AES128-SHA256 |
√ |
√ |
√ |
√ |
√ |
ECDHE-RSA-AES256-SHA384 |
√ |
√ |
√ |
√ |
√ |
AES128-GCM-SHA256 |
√ |
√ |
√ |
√ |
- |
AES256-GCM-SHA384 |
√ |
√ |
√ |
√ |
- |
AES128-SHA256 |
√ |
√ |
√ |
√ |
- |
AES256-SHA256 |
√ |
√ |
√ |
√ |
- |
ECDHE-RSA-AES128-SHA |
√ |
√ |
√ |
- |
- |
ECDHE-RSA-AES256-SHA |
√ |
√ |
√ |
- |
- |
AES128-SHA |
√ |
√ |
√ |
- |
- |
AES256-SHA |
√ |
√ |
√ |
- |
- |
ECDHE-ECDSA-AES128-GCM-SHA256 |
√ |
√ |
√ |
√ |
√ |
ECDHE-ECDSA-AES128-SHA256 |
√ |
√ |
√ |
√ |
√ |
ECDHE-ECDSA-AES128-SHA |
√ |
√ |
√ |
- |
- |
ECDHE-ECDSA-AES256-GCM-SHA384 |
√ |
√ |
√ |
√ |
√ |
ECDHE-ECDSA-AES256-SHA384 |
√ |
√ |
√ |
√ |
√ |
ECDHE-ECDSA-AES256-SHA |
√ |
√ |
√ |
- |
- |
When you modify a security policy, ensure that the security group containing backend servers allows access from 100.125.0.0/16 and allows ICMP packets for UDP health checks. Otherwise, backend servers will be considered unhealthy, and routing will be affected.
and select the desired region and project.
in the upper left corner to display Service List and choose Network > Elastic Load Balancing.
on the right of its name.