Operational Defect Database

BugZero found this defect 334 days ago.

F5 | 1306249

Hourly spike in the CPU usage causing delay in TLS connections

Last update date:

5/17/2024

Affected products:

BIG-IP

BIG-IP Install/Upgrade

BIG-IP LTM

Affected releases:

16.1.2.2

16.1.3

16.1.3.1

16.1.3.2

16.1.3.3

16.1.3.4

16.1.3.5

16.1.4

16.1.4.1

16.1.4.2

16.1.4.3

17.0.0

Fixed releases:

No fixed releases provided.

Description:

3. Users may complain of slow connections once per hour, or timeouts may occur briefly once per hour. ... Impact ... TMM CPU Usage goes high for about one second, which may cause a delay in traffic handling, and the Idle Enforcer gets activated briefly. ... Conditions ... This issue occurs when the Clientssl profile is assigned to a virtual server and passing traffic. ... This happens during the normal operation while running an affected software version. ... Workaround ... When a workaround fix is applied via an EHF, a DB key is needed to be enabled for the fix to take effect. ... tmm.ssl.useffdhe It enables or disables the timely generation of FFDHE key pairs and the default value is set to true. ... When the db variable is true (enabled), BIG-IP will generate FFDHE key pairs periodically as usual. ... When the db variable is false (disabled), BIG-IP will disable the periodic generation of FFDHE key pairs of size >= 2048 bits. ... If ClientHello sends only DH groups during handsha...

Additional Resources / Links

Share:

BugZero® Risk Score

What's this?

Coming soon

Status

Verified

Learn More

Search:

...