Bug ID 542472: SSL::disable for alerts does not take effect and first alert fails

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP FPS(all modules)

Known Affected Versions:
11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4, 11.6.0 HF5, 11.6.0 HF6, 11.6.0 HF7, 11.6.0 HF8, 12.0.0, 12.0.0 HF1, 12.0.0 HF2

Fixed In:
12.1.0, 12.0.0 HF3, 11.6.1

Opened: Aug 30, 2015

Severity: 3-Major

Symptoms

Command 'SSL::disable serverside' fails when sending alerts.

Impact

Alert may take a very long time (more than 30 seconds) to receive a response from the alert server.

Conditions

The alert is received on an already established clientside TCP connection that has a current connection through to the regular virtual server pool member.

Workaround

To resolve the issue, add a OneConnect profile to the virtual server, or use an iRule that performs an 'LB::detach' when a request is received for /rstats/.

Fix Information

Command 'SSL::disable serverside' now completes successfully when sending alerts.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips