Bug ID 572256: SSH Proxy connections drop after a period of time/after a certain amount of data has been transferred

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP AFM(all modules)

Fixed In:
12.1.0

Opened: Feb 06, 2016

Severity: 3-Major

Symptoms

SSH Proxy connections drop after a period of time/after a certain amount of data has been transferred, based on the 'RekeyLimit' settings in sshd_config. It is possible that a 'fingerprint changed'/'REMOTE HOST IDENTIFICATION HAS CHANGED' error will appear on the terminal of the SSH client.

Impact

Dropped connections.

Conditions

Always, after a certain amount of time/data has passed, unless the specified workaround is applied. Note: On many SSH installations, there will be no time-based automatic rekeying unless explicitly enabled.

Workaround

Upgrading to a fixed version is the best option, but a possible workaround is to set 'RekeyLimit' in sshd_config to a very high value, such as 'RekeyLimit 100G'.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips