Last Modified: Jul 18, 2026
Affected Product(s):
BIG-IP F5OS-A, SSLO, TMOS
Fixed In:
17.5.1.4, 17.1.3
Opened: Oct 10, 2023 Severity: 3-Major
In BIG-IP tenants launched on R4x00/R2x00 systems, configuring a MAC Masquerade address on the SSL Orchestrator egress port prevents traffic from passing
Egress traffic on the SSL Orchestrator port will be dropped on the physical NIC card. Hence, SSL Orchestrator egress traffic on the port wouldn't be received on the L2 device
-- R4x00 or R2x00 systems -- BIG-IP Tenant -- High availability (HA) configured in BIG-IP -- MAC Masquerade address configured on SSL Orchestrator egress port
Enable per-VLAN MAC masquerade, per K000141018
None