Bug ID 1818461: [APM][VPN][WIN] Tunnel can't be established if endpoint inspection is Skipped. Machine Hash is not maching

Last Modified: Jun 28, 2025

Affected Product(s):
BIG-IP APM, Install/Upgrade(all modules)

Known Affected Versions:
17.1.2, 17.1.2.1, 17.1.2.2

Fixed In:
17.5.1

Opened: Feb 13, 2025

Severity: 4-Minor

Symptoms

Because of selecting Skip Inspection button during EPI launch, it leads to in-correct machine hash and VPN connection is failed with below errors. err tmm1[18549]: 01230140:3: RST sent from 10.103.xx.xx:443 to 10.103.xx.xx:64086, [0x2ff9084:34740] Machine Hash is not Valid tmm1[18549]: 01230140:3: RST sent from 10.103.xx.xx:443 to 10.103.xx.xx:64123, [0x2ff9084:4239] Access encountered an error (Operation not supported)

Impact

TCP connection reset is encountered and VPN connection fails.

Conditions

-- Endpoint inspection is enabled in access policy, add Advanced resources assignment for fallback branch and end with allow -- Launch endpoint inspection, select Skip Inspection instead of Start Inspection If you are upgrading, this can be encountered after upgrading to version 17.1.2 and APM client (7250 or 7251).

Workaround

Instead of Skip Inspection, select Start Inspection (Or) Don't configure any EPI check in Access policy

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips