Bug ID 1038629: DTLS virtual server not performing clean shutdown upon reception of CLOSE_NOTIFY from client

Last Modified: Nov 07, 2022

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
13.1.0,,,,,,,,, 13.1.1,,,,, 13.1.3,,,,,,, 13.1.4,, 14.1.0,,,,,, 14.1.2,,,,,,,,, 14.1.3,, 14.1.4,,,,, 15.1.0,,,,,, 15.1.1, 15.1.2,, 15.1.3,, 15.1.4,, 16.1.0, 16.1.1, 16.1.2

Fixed In:
17.0.0,, 15.1.5,, 13.1.5

Opened: Aug 04, 2021

Severity: 3-Major


With the DTLS virtual server, when client sends the CLOSE_NOTIFY alert, BIG-IP is simply closing the connection without sending the CLOSE_NOTIFY back to client as well as the backend server. This causes the backend server to not close/shutdown the connection completely.


Backend server and client will have a dangling connection for certain period of time (Based on the timeout implementation at the respective ends).


This issue occurs with all DTLS virtual servers which has associated client-ssl and server-ssl profiles.



Fix Information


Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips