config controller tls13-cipher
Focus
Focus
Prisma SD-WAN

config controller tls13-cipher

Table of Contents

config controller tls13-cipher

Use the config controller tls13-cipher command to select a specific TLS 1.3 cipher suite for MRL (Multi-Relay Layer) connections between the ION device and the Strata Cloud Manager controller. Each cipher suite combines an AEAD (Authenticated Encryption with Associated Data) algorithm with a hash function.

Command

config controller tls13-cipher <cipher-suite>

Options

TLS_AES_256_GCM_SHA384AES-256 in GCM mode with SHA-384. Recommended for high security environments.
TLS_AES_128_GCM_SHA256AES-128 in GCM mode with SHA-256. Provides balanced security and performance.
TLS_CHACHA20_POLY1305_SHA256ChaCha20-Poly1305 stream cipher with SHA-256. Optimized for software implementations.
TLS_AES_128_CCM_SHA256AES-128 in CCM mode with SHA-256.
TLS_AES_128_CCM_8_SHA256AES-128 in CCM mode with 8-byte authentication tag and SHA-256.

Command Notes

RoleSuper
Related Commands
config controller tls13
dump controller cipher
dump controller mrl-tlsinfo
Introduced inRelease 6.8.1

Example

Select the TLS_CHACHA20_POLY1305_SHA256 cipher suite:
config controller tls13-cipher TLS_CHACHA20_POLY1305_SHA256 TLS 1.3 cipher suite configured
Select the TLS_AES_256_GCM_SHA384 cipher suite for high security:
config controller tls13-cipher TLS_AES_256_GCM_SHA384 TLS 1.3 cipher suite configured