Bug ID 1038629: DTLS virtual server not performing clean shutdown upon reception of CLOSE_NOTIFY from client

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP LTM(all modules)

Fixed In:
17.0.0, 16.1.2.1, 15.1.5, 14.1.4.5, 13.1.5

Opened: Aug 04, 2021

Severity: 3-Major

Symptoms

With the DTLS virtual server, when client sends the CLOSE_NOTIFY alert, BIG-IP is simply closing the connection without sending the CLOSE_NOTIFY back to client as well as the backend server. This causes the backend server to not close/shutdown the connection completely.

Impact

Backend server and client will have a dangling connection for certain period of time (Based on the timeout implementation at the respective ends).

Conditions

This issue occurs with all DTLS virtual servers which has associated client-ssl and server-ssl profiles.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips