Bug ID 502683: Traffic intermittently dropped in syncookie mode, especially when hardware syncookie is on

Last Modified: Feb 13, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
11.5.0, 11.5.1, 11.5.1 HF1, 11.5.1 HF10, 11.5.1 HF11, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.2, 11.5.2 HF1, 11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4

Fixed In:
12.0.0, 11.6.0 HF5, 11.5.3

Opened: Jan 23, 2015
Severity: 3-Major
Related AskF5 Article:
K16481

Symptoms

In certain corner cases, BIG-IP software rejects valid SYN-Cookie responses due to incorrect hardware algorithm masking on the software side.

Impact

Intermittent connection failures.

Conditions

This issue appears only on hardware-SYN-Cookie-capable platforms when running the hardware SYN-Cookie algorithm.

Workaround

Run software SYN-Cookie algorithm. Use the DB variable. This makes sure software is running correct generation and validation algorithm.

Fix Information

Traffic is now handled correctly in certain corner cases involving hardware syncookies.

Behavior Change