Bug ID 2219721: In explicit topology TCP handshake might be incomplete

Last Modified: Mar 03, 2026

Affected Product(s):
BIG-IP SSLO(all modules)

Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4, 17.5.1.5

Opened: Feb 03, 2026

Severity: 3-Major

Symptoms

BIG-IP occasionally resets client connections, with the RST cause reported as "Detaching server side before server connect"

Impact

When the policy rejects the ClientHello due to the hostname, the connection ends up getting reset with the cause reported as "Detaching server side before server connect".

Conditions

-- Explicit topology -- Policy with early reject -- The policy rejects on the ClientHello while the server-side TCP connection is being established

Workaround

Enable the transparent virtual verified-accepted setting. This ensures that the server-side completes the three-way handshake before sending RST.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips