For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

rmd1023's avatar
rmd1023
Icon for Nimbostratus rankNimbostratus
Apr 08, 2015

Running into bug 226042 with IIS - any workaround from either server or LTM side?

I'm running LTM version 10.2.1, and in the past few weeks I've suddenly started having issues with Windows servers (both IIS and Windows Apache) doing SSL bridging. It looks like I'm running into bug 226042, which seems to be triggered by the server padding SSL replies to make the packets all of a uniform size. I assume Windows started doing this as part of a hotfix after one of the several recent crypto/ssl exploits that have hit the news (POODLE, maybe?). The failure mode is that small files will pass through, but anything over about 17K will get a connection reset and a message in the logs like this: http_process_state_prepend - Invalid action EV_INGRESS_DATA during ST_HTTP_PREPEND_HEADERS (Server side: vip=myvip-443 profile=http pool=lb-mypool-443)

 

Are other folks with Windows servers seeing this? Is this becoming a problem for other folks or am I just lucky? Anyone run into this and found a workaround from either the server side or the LTM side? Right now the only workaround I have is doing SSL offload instead of SSL bridging and running the connection from the LTM to the server in the clear on HTTP, but I'd like to be able to offer SSL bridging.

 

Thanks!