Updated on 2026-08-26 GMT+08:00

Modify TLS Configuration

After a domain name is connected to Advanced Anti-DDoS, you can set a proper TLS version and cryptographic algorithm suite for the connected domain name. This section describes how to configure TLS.

Access is denied for requests from TLS versions older than the minimum TLS version.

Supported TLS Versions

Advanced Anti-DDoS allows you to upload international standard HTTPS certificates. The following table describes the TLS versions of the uploaded certificates supported by default.

Table 1 Supported TLS versions

Certificate Type

TLS Version Supported by Default

TLS Version That Can Be Modified

International standard HTTPS certificate

By default, Advanced Anti-DDoS supports the following LTS versions: TLS v1.0, TLS v1.1, TLS v1.2.

TLS versions and cipher suites that can be modified:

  • TLS v1.0, TLS v1.1, and TLS v1.2 are supported. These versions have high compatibility but limited security.
  • TLS v1.1 and later versions (TLS v1.1 and TLS v1.2) are supported. These versions have high compatibility and security.
  • TLS v1.2 and later versions (TLS v1.2) are supported. These versions have high compatibility and security.

Modify TLS Configuration

  1. Log in to the AAD console.
  2. In the navigation pane on the left, choose Advanced Anti-DDoS > Domain Name Access. The Domain Name Access page is displayed.
  3. Click Edit next to TLS Configuration of the target domain name.
  4. After selecting the TLS version and cipher suite, click Confirm.

    Figure 1 Forwarding rule fields