Forum Discussion
F5 impact for fastL4 reassemble-fragments option (CVE-2015-4638)
FYI
F5 support told me about this
Enabling the Reassemble-Fragments option on a fastL4 virtual will make the LTM wait for all fragments of a (fragmented) packet, before passing the completed packet to the serverside. This may introduce some initial latency as the packet fragments arrive and are assembled, but will utilise serverside networks settings to deliver larger complete packets (or fragments) to the pool member.
Overall, this setting should be mostly neutral in impact. However, as every network traffic pattern may be different and your specific environment is unknown, we do recommend testing this change and monitoring closely to ensure that there are no adverse impacts in your environment.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com