Forum Discussion
yuce_sungur_100
Nimbostratus
Apr 13, 2010tcp half open
The f5 3400 box , we have has BIG-IP 10.0.1 build 283.It seems like when "tcp half open" monitor is set for a pool,F5 is not sending reset packets when it receives "syn-ack" from the pool member.
Any idea?misconfiguration or system bug ?
1 Reply
- hoolio
Cirrostratus
Hi ysungur,
According to SOL9812, LTM should send a RST after getting the SYN ACK. If you're not seeing this, you could open a case with F5 Support and ask them if the expected behavior has changed in v10.x or if this is a bug.
https://support.f5.com/kb/en-us/solutions/public/9000/800/sol9812.html
Certain BIG-IP monitors use a TCP RST packet to close the monitor connection quickly. For example, the tcp_half_open monitor performs a simple check on the pool member service by sending a TCP SYN packet to the service port. When the monitor receives the SYN-ACK packet from the pool member, the monitor considers the service to be up, and sends a TCP RST packet to the service instead of completing the three-way handshake. The TCP RST packet is typically sent on the server side of the connection, and the source IP address of the reset is the relevant self IP address of the VLAN.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
