Bug ID 698599: Cave Creek Crypto HW accelerated SSL traffic may encounter errors and performance problems.

Last Modified: Jan 31, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4

Opened: Dec 12, 2017
Severity: 3-Major
Related AskF5 Article:
K24479486

Symptoms

Cave Creek Hardware-accelerated Secure Sockets Layer (SSL) traffic may encounter errors and performance problems. The BIG-IP system may experience SSL connection failures or reduced performance. Following logs show an example of errors seen: /var/log/ltm -- crit tmm3[11707]: 01010025:2: Device error: crypto codec qa-crypto3-3 queue is stuck. -- warning tmm3[11707]: 01260009:4: Connection error: ssl_basic_rx:1015: decrypt request error (20)

Impact

The BIG-IP system may experience SSL connection failures or reduced performance.

Conditions

This issue occurs when all of the following conditions are met: -- Your BIG-IP system uses Cave Creek SSL hardware acceleration. -- You are experiencing a high SSL traffic load.

Workaround

To work around this issue, you can increase the crypto.queue.timeout database key. To do so, perform the following procedure: Impact of workaround: Performing the following procedure should not have a negative impact on your system. This procedure will mitigate future occurrences. A reboot of the BIG-IP system is required to clear a currently occurring condition. 1. Log in to the Traffic Management Shell (tmsh) as an administrative user. 2. Run the following command: modify /sys db crypto.queue.timeout value 300 3. Reboot the BIG-IP system.

Fix Information

None

Behavior Change