Bug ID 1251173: SNI based redirection using LTM policies is not working in BIG-IP

Last Modified: Oct 04, 2024

Affected Product(s):
BIG-IP None(all modules)

Known Affected Versions:
16.1.2, 16.1.2.1, 16.1.2.2, 16.1.3, 16.1.3.1, 16.1.3.2, 16.1.3.3, 16.1.3.4, 16.1.3.5, 16.1.4, 16.1.4.1, 16.1.4.2, 16.1.4.3, 16.1.5, 16.1.5.1

Opened: Feb 23, 2023

Severity: 3-Major

Symptoms

When an LTM policy uses server-name as the condition to route traffic to different virtual servers, the expected virtual server is not always chosen.

Impact

The traffic is routed through a different virtual server than the expected one.

Conditions

The issue can be seen when the following are true: 1. BIG-IP has more than one virtual server. 2. There is an LTM policy with server-name based conditions and actions.

Workaround

This issue only affects requests involving TLSv1 protocol negotiation. Enforcing usage of TLSv1.1 or higher protocol version can prevent the issue.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips