NTLM-authenticated applications lose session and require repeated logins due to a 401 Unauthorized error caused by a change in AVI's connection handling behavior when a non-2xx response is received while the client request body is still in transit.
Affected Avi version: 30.2.7, 31.x, 32.1.2
This issue is caused by a recent change in AVI's behavior when handling non-2xx responses (Refer KB https://knowledge.broadcom.com/external/article/437430 ):
Workaround
Enable Request Body Buffering in the HTTP Application Profile to prevent the connection from being closed mid-handshake.
Steps:
NOTE: This workaround is applicable to small Post bodies; and may not be suitable for applications, which work with large Post bodies.
Action Plan/Fix
A permanent fix for this issue is released in 30.2.7-2p1 patch and available to download (refer to release notes Release Notes for VMware Avi LB v30.2.7-2p1), and is also scheduled to be released in the following future versions of Avi LB software: 31.2.x, and 32.1.x