Configure support for HTTP strict transport security (HSTS)
maxage parameter to specify that HSTS is in force for that duration for that client. By default, the HSTS header applies only to the root domain. You can specify whether subdomains must be included. For example, you can specify that subdomains for www.example.com, such as www.abc.example.com and www.xyx.example.com, can be accessed only using HTTPS by setting the IncludeSubdomains parameter to YES. The subdomains must support HTTPS. However, they do not each need to have HSTS enabled.
maxage parameter to 31536000, the browser remembers to use only HTTPS to access the domain for one year.
Configure HSTS by using the CLI
add ssl vserver <vServerName> -maxage <positive_integer> -IncludeSubdomains ( YES | NO)
set ssl vserver <vServerName> -HSTS ( ENABLED | DISABLED )
add ssl profile <name> -maxage <positive_integer> -IncludeSubdomains ( YES | NO )
set ssl profile <name> -HSTS ( ENABLED | DISABLED )
Arguments
HSTS
State of HTTP Strict Transport Security (HSTS) on an SSL virtual server or SSL profile. Using HSTS, a server can enforce the use of an HTTPS connection for all communication with a client.
Possible values: ENABLED, DISABLED
Default: DISABLED
maxage
Set the maximum time, in seconds, in the strict transport security (STS) header during which the client must send only HTTPS requests to the server.
Default: 0
Minimum: 0
Maximum: 4294967294
IncludeSubdomains
Enable HSTS for subdomains. If set to Yes, a client must send only HTTPS requests for subdomains.
Possible values: YES, NO
Default: NO
add ssl vserver VS-SSL –maxage 157680000 –IncludeSubdomain YES
set ssl vserver VS-SSL –HSTS ENABLEDadd sslProfile hstsprofile –maxage 157680000 –IncludeSubdomain YES
set sslProfile hstsprofile –HSTS ENABLED
Configure HSTS by using the GUI
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Select a virtual server of type SSL and click Edit.
-
Select an SSL profile and click Edit.
-
In Basic Settings, click the pencil icon to edit the settings. Scroll down and select HSTS and Include Subdomains.

-
In Advanced Settings, select SSL Parameters.
-
Select HSTS and Include Subdomains.

Support for HSTS preload
preload parameter in the SSL virtual server or SSL profile to YES. The appliance then includes the preload in the HTTP response header to the client. You can configure this feature using both the CLI and the GUI. For more information about HSTS preload, see <https://hstspreload.org/>.
Strict-Transport-Security: max-age=63072000; includeSubDomains; preloadStrict-Transport-Security: max-age=63072000; preload
Configure HSTS preload by using the CLI
add ssl vserver <vServerName> -maxage <positive_integer> -preload ( YES | NO )
set ssl vserver <vServerName> -HSTS ( ENABLED | DISABLED )
add ssl profile <name> -maxage <positive_integer> -IncludeSubdomains ( YES | NO ) -preload ( YES | NO )
set ssl profile <name> -HSTS ( ENABLED | DISABLED )
Configure HSTS preload by using the GUI
-
Navigate to System > Profiles > SSL Profiles. Select an SSL profile and click Edit.
-
In Basic Settings, click the pencil icon to edit the settings. Scroll down and select HSTS and Preload.

-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Select a virtual server of type SSL and click Edit.
-
In Advanced Settings, select SSL Parameters.
-
Select HSTS and Preload.

Use case
<http://www.exemple.com>. The browser detects the name exemple.com and communicates with the DNS server to get the IP address for the host server. The browser contacts the IP address by using port 80. The banking website redirects the request to <https://www.exemple.com>. An SSL handshake is performed resulting in establishing an SSL connection. The padlock in the URL changes to green and shows locked. User1 can now enter the credentials to make a transaction.
Problem Scenario
<https://www.example.com> (note the slight change in spelling). User1 might not notice the discrepancy (example.com instead of exemple.com) and enter the credentials.
Solution
add ssl profile sample-profile -maxage 63072000 -IncludeSubdomains YES -preload YES
set ssl profile sample-profile -HSTS ENABLED