Bug ID 891145: TCP PAWS: send an ACK for half-open connections that receive a SYN with an older TSVal

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
14.1.0,,,,,, 14.1.2,,,,,,,,, 14.1.3,, 14.1.4,,,,,,, 14.1.5,,,,,, 15.1.0,,,,,, 15.1.1, 15.1.2,, 15.1.3,, 15.1.4,, 15.1.5,, 15.1.6,, 15.1.7, 15.1.8,,, 15.1.9,, 15.1.10,,,, 16.1.0, 16.1.1, 16.1.2,,, 16.1.3,,,,,, 16.1.4,,,

Opened: Mar 19, 2020

Severity: 3-Major


SYNs received with TSVal <= TS.Recent are dropped without sending an ACK in FIN-WAIT-2 state.


The new TCP connection cannot infer the half-open state of Local TCP connections, which prevents faster recovery of half-open connections. The local TCP connection stays around for a longer time.


-- Timestamps are enabled in TCP profile. -- Local TCP connection is in FIN-WAIT-2 state. -- Remote TCP connection abandoned the flow. -- A new TCP connection sends a SYN with TSVal <= TS.Recent to the local connection.


There are two workarounds: -- Reduce the Fin Wait 2 timeout (the default: 300 sec) so that TCP connection is terminated sooner. -- Disable TCP Timestamps.

Fix Information


Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips