Forum Discussion
hui_37443
Nimbostratus
Feb 24, 2010auth_result fired twice?
We have implemented an iRule to do OCSP check, based on the prize winner http://devcentral.f5.com/Default.aspx?tabid=108. When it encounters an error, it doesn't resume the suspended SSL::handshake. ...
Craig_Reeve
Nimbostratus
Dec 13, 2010Hi Hui,
I hope I aren't way off base but have you tried changing your Auth Profile timeout to 310 secs?
Why do this you ask? My problem as I noted in a post above turned out to be a session that didn't get its final TCP FIN packet so it essentially waited for the TCP timeout of 300 secs which then caused the F5 to force a TCP RESET, which sometimes occurred at the same time as the AUTH 300 secs timeout. What I got in the AUTH Event was garbage data. Easy solution was to increase the AUTH timeout by 10 secs to 310 secs. I think the F5 ENE came up with this one as 1 of 3 possible solutions.
I didn't update my findings here as I thought the issue you had was completely different to mine but decided to monitor this thread just in case. Interestingly this issue (Improper FIN closure) was supposed to have been fixed in 10.2 so I am surprised it sounds like it is still there.
Hope this works for you as it took many emails and tcpdumps to get a satisfactory resolution to our issue.
Regards, Craig
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects