Last Modified: Jan 09, 2025
Affected Product(s):
BIG-IP AFM
Known Affected Versions:
15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4, 15.1.10.5, 15.1.10.6, 16.1.0, 16.1.1, 16.1.2, 16.1.2.1, 16.1.2.2, 16.1.3, 16.1.3.1, 16.1.3.2, 16.1.3.3, 16.1.3.4, 16.1.3.5, 16.1.4, 16.1.4.1, 16.1.4.2, 16.1.4.3, 16.1.5, 16.1.5.1, 16.1.5.2, 17.1.0, 17.1.0.1, 17.1.0.2, 17.1.0.3, 17.1.1, 17.1.1.1, 17.1.1.2, 17.1.1.3, 17.1.1.4
Fixed In:
17.1.2
Opened: Jul 16, 2024 Severity: 1-Blocking
The BIG-IP AFM hardware DoS protection is incompatible when the vCMP host or guest uses different versions (where one device runs BIG-IP version 17.1.0 or later and the other device runs a version lower than BIG-IP 17.1.0).
The BIG-IP system drops packets that may be legitimate, thus reducing throughput and disrupting the existing services. Because of this issue, one or more of the following symptoms may occur: -- Throughput is lower than expected. -- The BIG-IP system intermittently drops legitimate TCP connections.
- vCMP capable platform - vCMP enabled - DoS hardware offload enabled - The software version of the guest is lower than BIG-IP 17.1.0, and the host version is BIG-IP 17.1.0 or higher. Or - The software version of the host is lower than BIG-IP 17.1.0, and the guest version is BIG-IP 17.1.0 or higher.
You can resolve this issue by: Upgrading vCMP host to v17.1.2 OR Upgrading all guests to match vCMP host version. OR Disabling the hardware DoS protection on a vCMP guest using the TMSH modify /sys db dos.forceswdos value true command. This is should only be used as a last resort as there is possible risk from DOS attacks.
Added support for setting the DoS version in the hardware register based on the guest software version, thereby addressing the DoS vectors incompatibility for the vCMP platform when the host version is BIG-IP 17.1.0 or later and the guest version is before BIG-IP 17.1.0.