Loading...
Loading...
Following are the symptoms: 1. When the BIG-IP system's MTUs are larger than the smallest MTU in the end-to-end path: -- The BIG-IP system does not mark coalesced packets larger than egress MSS but smaller than egress MTU in the BIG-IP system for segmentation. Therefore, the BIG-IP system receives 'ICMP fragmentation needed' messages from an intermediate router which drops the packets when the Don't Fragment (DF) bit is set in IP header. 2. When the BIG-IP system's MTUs are less than 1500: -- On ingress, the BIG-IP system rejects coalesced packets larger than ingress MTU and less than 1500 and having DF bit set in IP header. the BIG-IP system sends 'ICMP fragmentation needed' message to sender.
No traffic or very low throughput.
* Generic Receive Offload (GRO) and Large Receive Offload (LRO) for data plane interfaces are supported and enabled (both in host and guest). * Packets are sent with DF bit set. * For #1: -- FastL4 profile in use. -- The BIG-IP system's VLAN MTUs are larger than the smallest MTU in the end-to-end path. * For #2: -- The BIG-IP system's MTUs are set to a value that is less than 1500. -- The packets' DF bits are set.
Disable LRO and GRO for data plane interfaces using the following command: tmsh modify sys db tm.tcplargereceiveoffload value disable. Note: For KVM virtio devices, LRO/GRO need to be turned off in host NIC.
The BIG-IP system fastL4 stack now uses discovered MSS to determine whether TCP segmentation is required.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.