Bug ID 878925: SSL connection mirroring failover at end of TLS handshake

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1

Fixed In:
16.0.0, 15.1.2, 14.1.4.1

Opened: Feb 08, 2020

Severity: 3-Major

Symptoms

In some cases, HTTP requests may fail if system failover occurs immediately after the TLS handshake finishes.

Impact

Connection might fail the HTTP request; in some cases, the server may reset HTTP 1.0 requests.

Conditions

-- System failover to standby device with SSL connection mirroring. -- Failover occurs immediately after the TLS handshake completes but before the HTTP request.

Workaround

None.

Fix Information

System now updates the high availability (HA) state at end of the TLS handshake to prevent this issue if failover occurs at end of the handshake but before client/server data.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips