Forum Discussion
iRule Event Agent in APM policy causes strange connection resets
I have an LTM with a simple test APM Policy like this and getting strange behaviour.
Start -> iRule Event Agent -> Logon Page -> Deny
When the iRule Event Agent block is present, the Logon Page is not displayed. I get connection reset in 80% cases. If I remove the iRule Event Agent block, the Logon page is always displayed correctly.
The iRule Event Agent block does absolutely nothing and has no iRule attached. TCPDUMP traces show internal F5 communications 127.20.1.3 -> 127.20.1.254 that end by SYN Timeouts.
Has anyone seen this kind of issues? The same APM policy works properly on another box.
Version: 11.4.1 HF9
3 Replies
- Josiah_39459Historic F5 Account
Yes, there are a number of issues with placing the irule event before the logon page (usually specific to the client: ios, vmware, etc). If you don't need to put it before the logon page, I would avoid it. If you must, please explain in more detail the workflow.
- mrichter
Nimbostratus
What are the number of issues? I am also experiencing this problem and need iRules to be invoked before certain login or display pages. Could you provide additional information?
- Stanislas_Piro2
Cumulonimbus
Hi,
if you need to execute some action before logon page, use irule event ACCESS_POLICY_STARTED instead of using irule event in VPE.
You can also execute some tcl code in variable assign.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com