Last Modified: Oct 16, 2019
See more info
Known Affected Versions:
13.1.0, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 220.127.116.11, 13.1.1, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 13.1.3, 220.127.116.11, 14.0.0, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 14.0.1, 14.1.0, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 14.1.2, 220.127.116.11, 15.0.0, 15.0.1
Opened: Aug 06, 2019
If a connection that has a fully closed client-side, but a server-side still in FIN_WAIT_2, receives a SYN matching the same connflow, the idle time is reset. This can result in the fin-wait-2-timeout never being reached. The SYN will be responded to with a RST - 'TCP Closed'
Connection may fail to be removed in a timely manner. New connection attempts are RST with 'TCP Closed'
- Client side connection has been fully closed. This may occur if a client SSL profile is in use and an 'Encrypted Alert' has been received. - Server side has sent a FIN which has been ACK'd, but no FIN has been received from the server. - SYN received matching the existing connflow before the FIN-WAIT-2-timeout has been reached (300 default).
You can use either of the following: -- Ensure servers are sending FIN's so as not to leave the connection in a FIN_WAIT_2 state. -- Mitigate the issue by lowering the FIN-WAIT-2-timeout to a smaller value, e.g., FIN-WAIT-2-timeout 10.