Bug ID 757441: Specific sequence of packets cause Fast Open being effectively disabled

Last Modified: Feb 15, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4

Opened: Feb 02, 2019
Severity: 2-Critical

Symptoms

You see this warning in the logs: warning tmm[21063]: 01010055:4: Syncookie embryonic connection counter -1 exceeded sys threshold 64000

Impact

TCP Fast open is disabled as the pre_established_connections becomes very large (greater than a threshold).

Conditions

TCP Fast Open and ECN are both enabled and multiple RST segments from the receive window are received in SYN_RECEIVED state.

Workaround

TCP ECN option can be disabled.

Fix Information

None

Behavior Change