Forum Discussion
We're working with Fishnet Security at the same time on this. We've taken tcpdumps and ssldumps on both nics (leading external and leading to the node vlan), and depending on how you read the results, it does appear the resets are originating from the BigIP LTM and being sent to the client. The web server never sees any of this. There's a question whether or not the resets could be coming from the Nokia/Checkpoint device that sits between the LTM and the Interwebs, but the general consensus is it's coming from the LTM.
We've turned off oneconnect transformations, pipelining and all compression, it's made no difference.
We have to launch this major release tonight, so we had development roll the code back in our non-prod environments. They preserved an example of the problem in our eyechart page. Go here:
https://pre.hallmarkbusiness.com/eyechart.aspx
and click on the second "download printable award" link. Then try opening the pdf you just downloaded - Acrobat Reader will say it's corrupt. The first ~500k isn't corrupt, it's just missing the rest.