Bug ID 1104517: In SWG explicit proxy, some TCP connections are reset because of inconsistency between sessionDB and local IP2SessionId map

Last Modified: Apr 24, 2024

Affected Product(s):
BIG-IP SWG(all modules)

Known Affected Versions:
15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 16.1.4, 16.1.4.1, 16.1.4.2, 16.1.4.3, 17.1.0.2, 17.1.0.3

Fixed In:
17.1.1, 15.1.10

Opened: May 05, 2022

Severity: 2-Critical

Symptoms

Some clients' TCP connections are reset with an error "cl sm driver error (Illegal value)" when the BIG-IP system is in this error state.

Impact

Some clients are unable to access a service.

Conditions

SWG explicit proxy is configured.

Workaround

Disable sessionDB mirroring on both active and standby # tmsh modify sys db statemirror.mirrorsessions value disable # tmsh save sys config Restart tmm on standby # bigstart restart tmm

Fix Information

Fixed an issue causing a TCP reset with certain clients.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips