Bug ID 1075729: Virtual server may not properly exit from hardware SYN Cookie mode

Last Modified: Dec 07, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 15.1.4, 15.1.4.1, 15.1.5

Fixed In:
17.1.0, 15.1.5.1, 14.1.5.1

Opened: Jan 25, 2022

Severity: 3-Major

Symptoms

Virtual servers do not exit hardware SYN Cookie mode even after the SYN flood attack stops. The TMSH 'show ltm virtual' output shows 'full hardware' mode.

Impact

The affected virtual server will not receive TCP SYN packets until TMM is restarted. The limited range of MSS values in SYN Cookie mode may slightly affect performance.

Conditions

-- VELOS and rSeries platforms. -- SYN cookie mode is triggered.

Workaround

Disable HW SYN Cookie mode on all virtual servers.

Fix Information

Virtual server is now fully exits hardware SYN Cookie mode once a SYN flood attack stops.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips