Bug ID 1510477: RD rule containing zones does not match expected traffic on the Network firewall policy

Last Modified: Sep 27, 2024

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
17.1.0, 17.1.0.1, 17.1.0.2, 17.1.0.3, 17.1.1, 17.1.1.1, 17.1.1.2, 17.1.1.3, 17.1.1.4

Opened: Feb 12, 2024

Severity: 3-Major

Symptoms

The ICMP packets are dropped based on the default match rule, instead of the RD rule match.

Impact

The ICMP packets are dropped based on the default match rule instead of using the RD rule match to drop.

Conditions

ICMP firewall policies created with Zone include Route Domain (RD) with two or more VLANs in the created Zone.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips