Bug ID 698599: Cave Creek Crypto HW accelerated SSL traffic may encounter errors and performance problems.

Last Modified: Apr 29, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1

Opened: Dec 12, 2017
Severity: 3-Major
Related AskF5 Article:
K24479486

Symptoms

Cave Creek Hardware-accelerated Secure Sockets Layer (SSL) traffic may encounter errors and performance problems. The BIG-IP system may experience SSL connection failures or reduced performance. Following logs show an example of errors seen: /var/log/ltm -- crit tmm3[11707]: 01010025:2: Device error: crypto codec qa-crypto3-3 queue is stuck. -- warning tmm3[11707]: 01260009:4: Connection error: ssl_basic_rx:1015: decrypt request error (20)

Impact

The BIG-IP system may experience SSL connection failures or reduced performance.

Conditions

This issue occurs when all of the following conditions are met: -- Your BIG-IP system uses Cave Creek SSL hardware acceleration. -- You are experiencing a high SSL traffic load.

Workaround

To work around this issue, you can increase the crypto.queue.timeout database key. To do so, perform the following procedure: Impact of workaround: Performing the following procedure should not have a negative impact on your system. This procedure will mitigate future occurrences. A reboot of the BIG-IP system is required to clear a currently occurring condition. 1. Log in to the Traffic Management Shell (tmsh) as an administrative user. 2. Run the following command: modify /sys db crypto.queue.timeout value 300 3. Reboot the BIG-IP system.

Fix Information

None

Behavior Change