Last Modified: Feb 12, 2025
Affected Product(s):
BIG-IP TMOS
Known Affected Versions:
16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2, 16.1.0, 16.1.1, 16.1.2, 16.1.2.1, 16.1.2.2, 16.1.3, 16.1.3.1, 16.1.3.2, 16.1.3.3, 16.1.3.4, 16.1.3.5, 16.1.4, 16.1.4.1, 16.1.4.2, 16.1.4.3, 16.1.5, 16.1.5.1, 16.1.5.2, 17.0.0, 17.0.0.1, 17.0.0.2, 17.1.0, 17.1.0.1, 17.1.0.2, 17.1.0.3, 17.1.1, 17.1.1.1, 17.1.1.2, 17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1
Opened: Feb 05, 2025 Severity: 2-Critical
IPsec IKEv1 tunnels fail half way through tunnel negotiation. As a result the tunnel never comes up.
IPsec tunnels are not able to connect remote peer networks.
-- BIG-IP with IKEv1 IPsec tunnel -- ISAKMP traffic to the remote peer is not in route-domain 0 (RD0) -- Upgrade to version 16.x or 17.x
There are two options: -- Use IKEv2, this will require that the remote peer is also reconfigured to IKEv2. -- Alternatively, move the IPsec peer's configuration to RD0.
None