Forum Discussion
Running into bug 226042 with IIS - any workaround from either server or LTM side?
I'm running LTM version 10.2.1, and in the past few weeks I've suddenly started having issues with Windows servers (both IIS and Windows Apache) doing SSL bridging. It looks like I'm running into bug 226042, which seems to be triggered by the server padding SSL replies to make the packets all of a uniform size. I assume Windows started doing this as part of a hotfix after one of the several recent crypto/ssl exploits that have hit the news (POODLE, maybe?). The failure mode is that small files will pass through, but anything over about 17K will get a connection reset and a message in the logs like this: http_process_state_prepend - Invalid action EV_INGRESS_DATA during ST_HTTP_PREPEND_HEADERS (Server side: vip=myvip-443 profile=http pool=lb-mypool-443)
Are other folks with Windows servers seeing this? Is this becoming a problem for other folks or am I just lucky? Anyone run into this and found a workaround from either the server side or the LTM side? Right now the only workaround I have is doing SSL offload instead of SSL bridging and running the connection from the LTM to the server in the clear on HTTP, but I'd like to be able to offer SSL bridging.
Thanks!
1 Reply
It looks like LTM received unexpected HTTP data, may be that is not complaint with RFC2616.
Please review article : https://support.f5.com/kb/en-us/solutions/public/5000/900/sol5922.html
For workaround you can remove http profile from the configuration and see if that helps.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com