Bug ID 975597: Using global variables in iRules causes TCP connections to reset with msg 'No flow found for ACK'

Last Modified: Apr 29, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1

Opened: Dec 21, 2020
Severity: 3-Major

Symptoms

When source port is reused toward a TCP virtual server with CMP disabled or in single-CPU mode, a RST might be returned with a cause 'No flow found for ACK'.

Impact

Unexpected RST events occur on the client side.

Conditions

-- TCP virtual server with CMP disabled, or in single-CPU mode. (For example, configuring an iRule that uses global variables is one way to put the system into single-CPU mode.) -- The client connection reuses the same TCP port as it used for a recently closed connection.

Workaround

You can use either of the following workarounds: -- Enable CMP. -- Modify the iRule (e.g., use a static namespace instead) to make it CMP capable.

Fix Information

None

Behavior Change