Bug ID 725625: BIG-IP VE Cryptographic Offload updated to Intel QAT 1.7 v4.4.0 SDK

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2

Fixed In:
15.0.0, 14.1.0.3

Opened: Jun 25, 2018

Severity: 3-Major

Symptoms

Data compression offload to QuickAssist devices is now enabled as part of BIG-IP Virtual Edition (VE) Cryptographic Offload feature. BIG-IP VE Cryptographic Offload uses the Intel QAT 1.7 SDK. A newer QAT 1.7 SDK v4.4.0 provides code and firmware that fixes several known QAT defects, including a compression defect specific to Lewisburg/Lewis Hill QuickAssist devices.

Impact

BIG-IP VE Cryptographic and Compression offload are more reliable. The QAT 1.7 v4.4.0 SDK should be installed on the hypervisor host.

Conditions

-- BIG-IP VE SSL Offload is licensed -- The BIG-IP VE VM has been assigned QAT Virtual Functions.

Workaround

None.

Fix Information

Several Intel QuickAssist defects have been fixed for BIG-IP VE Cryptographic and Compression Offload by upgrading BIG-IP VE to the Intel QAT 1.7 v4.4.0 SDK. This newer QAT SDK introduces code and firmware support to fix several defects. A new Compress and Verify mode is introduced to work around a compression defect specific to Lewisburg/Lewis Hill QuickAssist devices. See Intel's QuickAssist Release Notes for additional details: https://01.org/sites/default/files/downloads//336211-009qatrelnotes.pdf.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips