Citrix ADC crash when doing load test for TLS 1.3

Citrix ADC crash when doing load test for TLS 1.3

book

Article ID: CTX310777

calendar_today

Updated On:

Description

ADC crashes suddenly when doing load test for TLS 1.3

Resolution

Upgrade to the version 13.0-79.64 or newer versions.

Problem Cause

This is a known issue on Citrix ADC version 13.0 build 76.31 or older version and occurs when:

1. TLS 1.3 is negotiated for the connection (this specific issue does not exist in TLS 1.2 and below)

2. MPX /SDX platform uses Coleto Creek crypto offload chips (VPX and Cavium boxes are unaffected)

3. There is increased internal backpressure from the Intel Coleto Creek crypto chip. A "sustained overload" test (where ADC as a whole is subjected to high, sustained load greater than its rated capacity) can trigger this issue, and this issue can also be triggered by a short-term transient, rise in backpressure from the Coleto Creek chip.