Forum Discussion
ali_64819
Feb 27, 2012Nimbostratus
F5 Big-Ip upgraded to 11.1, "Open SSL error - error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure" and many other errors
Hello everyone, can anybody help me in resolving these errors.
i have recently upgraded F5 Big-Ip from 10.2 to 11.1 and recieving the following errors. 1. "Open ssl error -error:140790E5:SSL routines:SSL23 _WRITE:ssl handshake failure" (Navigating to System-->logs --> local traffic) 2. F5 big-IP is not sending all the logs to LOG Management system (Symantec SIM). Logs related to ASM are not present in the Symantec SIM, although i use to recieve the logs before the upgrade, F5 is only sending Partial logs to Symantec SIM, i can only view LTM Logs and some ASM LOGs which are of severity info,notice in Symantec SIM.
- Moe_JartinCirrusAgreed. The fix for us was to remove the SSL health check one-by-one from each of the pools. We finally found one pool that was causing the issue. To be clear though, this is not a problem with the pool but rather a change in behavior on the F5 side from 10.x to 11.x. I still think F5 needs to fixed the issue or give the option to ignore untrusted certs for health checks (or whatever is the root cause of the error).
- emilio_104458NimbostratusPosted By nitass on 07/09/2012 07:30 AM
https HTTPS Common
https_443 HTTPS Common
https_head_f5 HTTPS Common
- nitassEmployeecan you list all the https monitors you have?
- emilio_104458NimbostratusPosted By nitass on 07/09/2012 08:28 AM
- nitassEmployeei am not sure but would you mind trying custom https monitor with cipherlist ALL instead?
root@ve10(Active)(tmos) list ltm monitor https myhttps ltm monitor https myhttps { cipherlist "ALL" compatibility "enabled" defaults-from https destination *:* interval 5 send "GET /\r\n" time-until-up 0 timeout 16 }
- emilio_104458Nimbostratusnothing :(
- nitassEmployeeis the pool member really running https service?
- emilio_104458Nimbostratus[root@f5:Active] config curl https://192.168.32.129:443
- nitassEmployee[root@f5:Active] config curl https://192.168.32.129:443 can you try "-Ik" option? will you still get an error?
- emilio_104458Nimbostratuswith -IK opation, works
Recent Discussions
Related Content
Â
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects