Last Modified: Sep 18, 2026
Affected Product(s):
BIG-IP TMOS
Known Affected Versions:
17.1.0, 17.1.0.1, 17.1.0.2, 17.1.0.3, 17.1.1, 17.1.1.1, 17.1.1.2, 17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1, 17.1.2.2, 17.1.3, 17.1.3.1, 17.1.3.2, 17.1.3.4, 17.1.3.5, 17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4, 17.5.1.5, 17.5.1.6, 17.5.1.8, 17.5.1.9, 21.0.0, 21.0.0.1, 21.0.0.2, 21.0.0.3
Fixed In:
21.1.0
Opened: Feb 26, 2026 Severity: 2-Critical
When 2 or more ldap servers are configured for ldap authentication, auth fails due to timer expired (PAM timeout).
LDAP authentication fails due to PAM timeout- even when one of the servers responds with success.
-- Multiple ldap servers are configured for Remote-LDAP authentication -- The bind-timeout and search-timeout values are set to 30 seconds (this is the default)
Set the bind-timeout and search-timeout to lower values i.e 5 seconds
1. Configure BIG-IP for remote-LDAP authentication 2. Configure multiple LDAP servers (first few servers should be unreachable/not responding) 3. Test authentication from browser using remote user 4. Auth should be successful