For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Krys_Frankiewic's avatar
Krys_Frankiewic
Icon for Nimbostratus rankNimbostratus
Aug 28, 2015

Connection display issue.

Hello, we have two BIG-IP appliances running 11.5.2 version. When I run command 'show sys connection cs-server-addr' I'm getting different output. One is showing only client and VS IP addresses but not floting IP and server IP.

 

BIG-IP 1 show sys connection cs-server-addr 10.90.59.4

 

10.254.143.232:64677 10.90.59.4:443 any6.any any6.any tcp 3 (tmm: 0) none

 

BIG-IP 2 show sys connection cs-server-addr 10.151.15.4

 

10.254.143.232:64226 10.151.15.4:443 10.151.12.70:64226 10.151.124.20:443 tcp 3 (tmm: 0) none

 

Any idea why. Is there speciffic setting to show IP addresses instead any6.any?

 

5 Replies

  • I think the ones with any6.any any6.any are client-side connections with no corresponding server side connections yet in the case of LTM.

     

    In the case of APM, they may represent client-side connections still doing policy evaluation and accessing content only from the APM.

     

    cheers.

     

  • But the one with any6.any any6.any never show server connection. One appliance show the other doesn't, for the same URL (application).

     

  • Is the application SSL ? and maybe the client connection is not finishing the SSL handshake ?

     

    What about problem reproduction ? Do you consistently get the behavior with the device ?

     

  • Yes, it is SSL connection. Client is finishing the handshake with the F5, then transaction to the server is on TCP 80 (HTTP). Also to the same VS we are allowing HTTP, in this case I do see all info in the log. 10.16.55.142:49941 10.152.33.4:80 10.152.5.70:49939 10.153.129.10:80 tcp 0 (tmm: 0) none 10.15.73.29:65179 10.152.33.4:443 any6.any any6.any tcp 7 (tmm: 0) none