Forum Discussion
APM) NA error "Configuration download failed"
Hello everyone
My client is currently using APM version 7253; prior to the OS upgrade, they were using version 7247.
The setup involves an inline configuration with an SSL VA positioned upstream of the APM.
Communication between the client and the SSL VA uses TLS 1.3, while communication between the SSL VA and the APM uses TLS 1.2.
VPN connections worked normally when using version 7247, but an "NA error" appears after upgrading to version 7253.
Has there been any change in TLS-related behavior between version 7247 and 7253?
Alternatively, has anyone else encountered a similar issue?
3 Replies
Hello,
Have a look in this articleThis may match known issue 1697301 in the APM Client 7.2.5.3 release notes. It states that on Windows 10, VPN connection with Edge Client/WebVPN/Machine Tunnel/Custom Dialer may fail when TLS 1.3 is used. In your topology, the client negotiates TLS 1.3 with the SSL VA, so the client-side connection is still TLS 1.3 even though the SSL VA talks to APM with TLS 1.2. As a test, force TLS 1.2 on the client-facing SSL VA profile or test from Windows 11. If TLS 1.2 fixes it, this is likely the known issue.
- RaNiAKeA
Nimbostratus
Thank you for the reply.
However, all the clients experiencing this issue were running Windows 11.
I am also curious about the fact that the client-SSL VA communicated successfully using TLS 1.3 with version 7.2.4.7 (whereas SSLVA-APM used TLS 1.2).
I would like to know if the upgrade from version 7.2.4.7 to 7.2.5.3 could be causing issues related to TLS reassembly on the intermediate SSL-VA.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com