Bug ID 2196597: TMM generates core when large firewall policy is attached to multiple virtual servers due to SOD watchdog timeout

Last Modified: Feb 03, 2026

Affected Product(s):
BIG-IP AFM, LTM(all modules)

Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4

Opened: Dec 27, 2025

Severity: 1-Blocking

Symptoms

-- TMM processes generate core dumps (SIGABRT) when activating firewall policies with high rule counts (20,000+ rules) across multiple virtual servers (20+) --- SOD (System Oversight Daemon) sends SIGABRT signal to TMM processes --- Observe the ltm log "sod[10802]: 01140041:5: Killing tmm.0 pid 23754."

Impact

Traffic disrupted while tmm restarts.

Conditions

1, Deploy couple of tenants with 8 slots on each Chasis 2, Set up an HA pair (Active/Standby). 3, Provision the system with LTM, AFM, and AVR modules. 4, Create a Network Firewall policy containing approximately 20,000 rules. 5, Attach the firewall policy to a virtual server. 6, Create 20 or more virtual servers, attaching the same firewall policy to each.

Workaround

Disable SOD Heartbeat Monitoring for all TMMs --- tmsh modify sys daemon-ha tmm heartbeat disabled.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips