Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alex-
Leader Leader
Leader

R80.40 Take 120 & VSX - Full HTTPS Inspection issue

Upgraded two unrelated VSX clusters to R80.40 Take 120 running full HTTPS inspection, and on each I began to notice choppy behaviour on web browsing, along with web-based applications beginning to fail.

When I switched back to the member still on Take 118, it worked directly. Then issues reappeared after going again to the Take 120 system. I refreshed the VS and pushed the policy but it didn't help. I rolled back to Take 118 and everything is peachy again, although I could have used the myriad of fixes introduced in Take 119. 🙂

On one of these clusters, HTTPSi was in evaluation so I can narrow it down to a couple of PC's and work with TAC, an SR is open.

I will post if I get relevant developments, I just wondered if others are using VSX + Take 120 + HTTPSi and having a similar issue.

0 Kudos
7 Replies
Naama_Specktor
Employee
Employee

Hi 🙂

 

We are not familiar with this issue , I will appreciate getting the SR number for better understanding. 

thanks!

Naama Specktor

0 Kudos
mcatanzaro
Employee
Employee

There was a rare issue discovered with T119 and T120 that sounds similar to what you are describing.

Are you seeing any parser errors in your logs?

Either way, if you have a TAC case open then you’re on the right path.

 

0 Kudos
Alex-
Leader Leader
Leader

@mcatanzaro There is a bunch of "F2P outbound processing failed (CPAS)", after a session with TAC they hint at SecureXL but additional debug sessions are planned during an upcoming maintenance window.

0 Kudos
maad-pul
Contributor

Did you find any solution for this problem? 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Are you already running a JHF version that includes the following?

PRJ-30818,
PRHF-19417
SecureXL In a rare scenario, after an upgrade, HTTPS traffic may be dropped.
CCSM R77/R80/ELITE
0 Kudos
maad-pul
Contributor

No, not yet. Take38 not GA for 81.10. I have seen that bug, but it just day HTTPS traffic not HTTPS Inspected traffic. Maybe a typo from CP? 

0 Kudos
Alex-
Leader Leader
Leader

I left the cluster on R80.40 Take 118 until R81 T44 became recommended and upgraded there and now Take 58, never had any HTTPS Inspection issues since.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events