Avi Controller UI and Shell Inaccessible After Modifying SSL protocols in Portal SSL Profile
search cancel

Avi Controller UI and Shell Inaccessible After Modifying SSL protocols in Portal SSL Profile

book

Article ID: 409670

calendar_today

Updated On:

Products

VMware Avi Load Balancer

Issue/Introduction

  • After modifying the SSL Profile used for the Avi Controller portal (default profile is System-Standard-Portal), all access to the Controller UI and shell (CLI) becomes unavailable.
  • This issue occurs specifically when the list of "Accepted Versions" for SSL/TLS protocols is configured with a non-consecutive selection.
  • For example, configuring TLS 1.0 and TLS 1.2 (skipping TLS 1.1), or TLS 1.1 and TLS 1.3 (skipping TLS 1.2), will trigger this condition.
  • Example screenshot of the offending configuration in the SSL profile:
  • Location of the SSL profile in System Settings:

Cause

This behavior is caused by a software defect in the Avi Controller's OpenSSL control plane logic. 

Resolution

This issue (Bug ID: AV-250259) is permanently resolved by upgrading to one of the following Avi Controller versions or any subsequent releases:

  • 30.2.7
  • 31.2.1

Workaround: Contact Broadcom Support for assistance in resolving this issue.