Bug ID 1182553: AFM blocks APM OAuth loopback call

Last Modified: Apr 17, 2024

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4

Opened: Oct 20, 2022

Severity: 3-Major

Symptoms

The OAuth protocol requires that the APM perform a loopback call to itself in order to pull details of a user. The packets sent by APM when sent over _loopback VLAN are being rejected by the default AFM rule. The _loopback is a non-configurable VLAN in firewall rules.

Impact

The OAuth virtual server is not working.

Conditions

-- APM is enabled. -- AFM is enabled.

Workaround

The _loopback is a non-configurable VLAN in firewall rules. Recommended workaround is to block all user-configured VLANs in the penultimate rule and then allow all in the last rule. This is less than ideal and would be prone to user error.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips