Bug ID 1677261: IPSec interop issue with Cisco device with AES-GCM algorithm

Last Modified: Feb 28, 2025

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1

Fixed In:
17.5.0

Opened: Sep 23, 2024

Severity: 4-Minor

Symptoms

A Cisco device cannot decrypt ESP packets sent by BIG-IP when AES-GCM algorithm is used.

Impact

IPSec fails. Data communication between the Cisco system and the BIG-IP system will not work when AES-GCM algorithm is used.

Conditions

-- IPSec -- The BIG-IP system is connected on the network to a Cisco system -- AES-GCM algorithm is used

Workaround

None

Fix Information

Data in the ESP packet is padded as per the standards.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips