config controller tls13
Focus
Focus
Prisma SD-WAN

config controller tls13

Table of Contents

config controller tls13

Use the config controller tls13 command to enable or disable TLS 1.3 for MRL (Multi-Relay Layer) connections between the ION device and the Strata Cloud Manager controller. TLS 1.3 provides enhanced security with quantum-resistant hybrid key exchange groups, reduced handshake latency, and improved privacy protection compared to TLS 1.2.

Command

config controller tls13 <enable|disable>

Options

enableEnable TLS 1.3 for controller connections. When enabled, the ION device uses TLS 1.3 with quantum-resistant hybrid key exchange groups for MRL connections to Strata Cloud Manager. This is the default setting for ION devices running software version 6.8.1 or later.
disableDisable TLS 1.3 and force connections to use TLS 1.2. Use this option only for troubleshooting or compatibility with older infrastructure components that do not support TLS 1.3.

Command Notes

RoleSuper
Related Commands
config controller tls13-cipher
dump controller cipher
dump controller mrl-tlsinfo
Introduced inRelease 6.8.1

Example

Enable TLS 1.3 for controller connections:
config controller tls13 enable TLS 1.3 enabled for controller connections
Disable TLS 1.3 and fall back to TLS 1.2:
config controller tls13 disable TLS 1.3 disabled for controller connections