Last Modified: Sep 02, 2026
Affected Product(s):
BIG-IP SSLO
Fixed In:
21.1.0.2, 17.5.1.9, 17.1.3.5
Opened: Sep 02, 2025 Severity: 1-Blocking
When a BIG-IP high-availability pair is properly configured and functioning as expected, the following iControl REST endpoint might return only the local device instead of both HA devices: /mgmt/shared/resolver/device-groups/tm-shared-all-big-ips/devices Consequently, applications or BIG-IP GUI workflows utilizing this endpoint may fail to display or recognize the HA peer. This issue has been reported to affect the SSL Orchestrator HA workflows related to the user interface
The high-availability (HA) pair may continue to show a healthy failover and configuration-sync status, but REST-based device discovery might provide incomplete information. As a result, management interfaces or integrations that rely on REST device discovery could mistakenly display only one device or fail to recognize the peer device
This issue occurs when all of the following conditions apply: - A BIG-IP high-availability pair is configured, and the HA relationship is otherwise healthy - The REST device-discovery endpoint is queried: /mgmt/shared/resolver/device-groups/tm-shared-all-big-ips/devices - The endpoint returns only the local BIG-IP device instead of both HA members
None
The issue was corrected in the REST device-discovery implementation