Bug ID 542472: SSL::disable for alerts does not take effect and first alert fails

Last Modified: Oct 16, 2023

Affected Product(s):
BIG-IP FPS(all modules)

Known Affected Versions:
11.6.0, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
12.1.0, 12.0.0 HF3, 11.6.1

Opened: Aug 30, 2015

Severity: 3-Major

Symptoms

Command 'SSL::disable serverside' fails when sending alerts.

Impact

Alert may take a very long time (more than 30 seconds) to receive a response from the alert server.

Conditions

The alert is received on an already established clientside TCP connection that has a current connection through to the regular virtual server pool member.

Workaround

To resolve the issue, add a OneConnect profile to the virtual server, or use an iRule that performs an 'LB::detach' when a request is received for /rstats/.

Fix Information

Command 'SSL::disable serverside' now completes successfully when sending alerts.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips