Last Modified: Jul 28, 2026
Affected Product(s):
BIG-IP (all modules)
Known Affected Versions:
15.1.10.4, 15.1.10.5, 15.1.10.6, 15.1.10.7, 15.1.10.8, 16.1.5, 16.1.5.1, 16.1.5.2, 16.1.6, 16.1.6.1, 17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1, 17.1.2.2, 17.1.3, 17.1.3.1, 17.1.3.2, 17.1.3.4
Opened: Aug 20, 2024 Severity: 3-Major
When remote authentication fallback is enabled, SSH access defaults to public-key authentication without attempting remote authentication (RADIUS or TACACS+). This behaviour is inconsistent, as RADIUS does not handle fallback as expected, unlike TACACS+.
Users relying on RADIUS for primary authentication may encounter issues where traffic does not reach the RADIUS server, despite fallback being enabled. This leads to inconsistent and unreliable authentication behaviour, preventing administrators from enforcing RADIUS authentication reliably.
1. Remote authentication is configured using RADIUS or TACACS+. 2. The fallback option is either enabled or disabled in the configuration. 3. Public-key authentication for SSH is enabled.
The only current workaround is to disable public-key authentication for SSH, ensuring the system attempts remote authentication via RADIUS or TACACS+. Refer to KB K67025432 for additional details regarding fallback behavior.
None