Bug ID 1377737: SSL Orchestrator does not pass traffic when MAC masquerading is configured on R4k or R2k systems

Last Modified: Jul 18, 2026

Affected Product(s):
BIG-IP F5OS-A, SSLO, TMOS(all modules)

Fixed In:
17.5.1.4, 17.1.3

Opened: Oct 10, 2023

Severity: 3-Major

Symptoms

In BIG-IP tenants launched on R4x00/R2x00 systems, configuring a MAC Masquerade address on the SSL Orchestrator egress port prevents traffic from passing

Impact

Egress traffic on the SSL Orchestrator port will be dropped on the physical NIC card. Hence, SSL Orchestrator egress traffic on the port wouldn't be received on the L2 device

Conditions

-- R4x00 or R2x00 systems -- BIG-IP Tenant -- High availability (HA) configured in BIG-IP -- MAC Masquerade address configured on SSL Orchestrator egress port

Workaround

Enable per-VLAN MAC masquerade, per K000141018

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips