Bug ID 1160973: Profile based allow list not working on L2 wire enabled interfaces in appliances

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP Velos(all modules)

Fixed In:
17.1.0

Opened: Sep 23, 2022

Severity: 3-Major

Symptoms

Attack mitigation is done in hardware for entries which are configured as allowed IPs in a DoS profile attached to virtual server.

Impact

Virtual server allow list functionality will not work as expected. Rate limiting will be done in hardware, although IP is configured to be allowed.

Conditions

- L2 wire need to be enabled. - Allow list need to be configured and attach to virtual server DoS profile. - Attack need to be detected for the traffic initiated from the source IP configured in allowed list.

Workaround

None

Fix Information

Allowed IP list on L2 wire enabled interfaces can be configured.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips