Forum Discussion

Muhammad_Irfan1's avatar
Dec 20, 2014

Time to time getting TCP handshake fail logs

We have 6 webservers. F5 is working in bridge mode. Client SSL terminates on F5 and from f5 to webserver is also HTTPS. Most of the logs are client tcp handshake fail but that is understandable because which don't have SSL cert handshake will fail. But why I am getting tcp handshake fails logs with webservers?

 

We are in full production and a lot of traffic is coming. Does getting this log after 10 to 20 minutes is OK or its a concern? why does handshake fails? is it because of webservers or because of F5.

 

1 Reply

  • Can you post the log message you are seeing? Most likely it is occurring because you server is unable to complete the three way handshake in the specified timeout period. That can be because of many different things including connection limits, port exhaustion, server load, etc...