Updating SSL profile by adding few more ciphers in application gateway.

Nagrath, Richa 21 Reputation points
2025-01-22T19:16:18.2866667+00:00

We want to choose customV2 however, we are getting below alert and post making the changes it does not give results.

What is the correct process of updating SSL profiles pertaining to few listeners in an application gateway.

Choosing a new predefined or customV2 policy improves the SSL security and performance for the entire gateway. The selected policy will thus automatically get applied to both SSL Policy and SSL Profile. You can choose to customize it later within the new policies

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,121 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Praveen Bandaru 250 Reputation points Microsoft Vendor
    2025-01-23T07:56:52.06+00:00

    Hello Nagrath, Richa
    Greetings!

    Thank you for your response!

    If you have an existing listener in your application gateway with a configured SSL policy, you can upgrade the same SSL policies in the associated listener.

    There are two methods to update:
    Step 1: Change the SSL policy from the listener.

    • Under the SSL Policy, you can select the change option to modify the SSL policy. You can choose the required cipher ID and save the changes.
      User's image

    Step 2: Change the SSL policies from the SSL settings.
    User's image

    Additionally, ensure that the supported cipher versions are checked, as there are some limitations in the application gateway.

    Reference doc: https://learn.microsoft.com/en-us/azure/application-gateway/application-gateway-configure-listener-specific-ssl-policy#associate-the-ssl-profile-with-a-listener
    Reference doc: https://learn.microsoft.com/en-us/azure/application-gateway/application-gateway-ssl-policy-overview?source=recommendations%22https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fazure%2Fapplication-gateway%2Fapplication-gateway-ssl-policy-overview%3Fsource%3Drecommendations%22#limitations


    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Regards,
    Praveen


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.