Stackexchange iconStackexchangeSep 10, 2026 ~1 min source read

Windows IPv6 flow label breaks TLS to Azure (dev.azure.com, portal.azure.com, and any other load balancers that hash on flow label) [closed]

Azure's load balancer hashes on the flow label (as RFC 6438 recommends), so the SYN and the ClientHello hash to different backends. I'm posting this here in the hope that someone at Microsoft sees it and decides to fix it.

Share this story

Send the public story page.

Useful takeaways from this story.

I'm posting this here in the hope that someone at Microsoft sees it and decides to fix it.

Also, so that other people who might be struggling with this strange, extremely hard to diagnose issue can quickly find the solution.

This error will affect you even if you've done everything right, as it's a bug in Microsoft's network stack.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

I'm posting this here in the hope that someone at Microsoft sees it and decides to fix it. Also, so that other people who might be struggling with this strange, extremely hard to diagnose issue can quickly find the solution. This is only relevant if you're in a network with IPv6 enabled and fully working...

How it works

  • This error will affect you even if you've done everything right, as it's a bug in Microsoft's network stack.
  • Root cause Windows sets a non-zero IPv6 flow label on the SYN, then zero on every subsequent packet of the same TCP connection.
  • Azure's load balancer hashes on the flow label (as RFC 6438 recommends), so the SYN and the ClientHello hash to different backends.

Details worth keeping

RFC 6437 §3 requires the flow label to be constant for the life of a flow. The second backend has no state for the connection and sends RST. Captured on the router's WAN interface, one connection, source port 49160: port 49160 flags[S] label=0x837f1 <- SYN carries a flow label port 49160 flags[.] label=ZERO <- ACK does not port 49160 flags[P.] label=ZERO <- ClientHello does not port 49160 flags[F.] label=0x837f1 <- FIN has it again p...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app