Bug ID 1773161: BIG-IP APM 17.1.2 VPN tunnels failed to establish at "GET /isession" stage

Last Modified: Jun 28, 2025

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
17.1.2, 17.1.2.1, 17.1.2.2

Fixed In:
17.5.1

Opened: Dec 16, 2024

Severity: 2-Critical

Symptoms

Windows Edgeclient (any other client) stuck at Initialisation. You may observe a lot of below logs in f5tunnelserver.txt 2024-12-15,12:32:26:530, 19084,19088,, 48, , 970, CUTunnelServerX::isReady(), server response , result=0 2024-12-15,12:32:27:035, 19084,19088,, 48, , 970, CUTunnelServerX::isReady(), server response , result=0 2024-12-15,12:32:27:541, 19084,19088,, 48, , 970, CUTunnelServerX::isReady(), server response , result=0 2024-12-15,12:32:28:046, 19084,19088,, 48, , 970, CUTunnelServerX::isReady(), server response , result=0

Impact

VPN fails to establish

Conditions

-- BIG-IP version with fix of ID 903501 -- "sys db ipv6.enabled" is set to FALSE -- Any client attempting to establish a VPN tunnel

Workaround

1. "sys db ipv6.enabled" is set to TRUE OR 2. Perform below two operations a) Disable the DB variable isession.ctrl.apm: tmsh modify sys db isession.ctrl.apm value disable b) Perform 'Apply Access Policy' for the access policy attached to the virtual server.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips