Bug ID 1166449: APM - NTLM authentication will stop working if any of DC FQDN is not resolvable in the configured DC list

Last Modified: Mar 30, 2024

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2

Fixed In:
17.1.0, 16.1.4, 15.1.9

Opened: Oct 03, 2022

Severity: 3-Major

Symptoms

NTLM authentication will stop working.

Impact

NTLM authentications targeted towards this NTLM Auth Config will start to fail.

Conditions

If any of the DC FQDN is not resolvable in the configured NTLM Auth Config DC list during below scenarios: - Create/Modify NTLM Auth Configuration - Restart ECA/NTLM service - Restart, Power cycle or after upgrade - Active/Stand by switch over.

Workaround

User need to remove the non-resolvable DC FQDN from the NTLM Auth configuration's DC list.

Fix Information

Fix will be provided to try FQDN resolution for all entries in the NTLM Auth configuration's DC list, NTLM Auth will proceed if at least one of the DC is resolvable and reachable.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips