Bug ID 2285529: IPS Attack Traffic Bypasses Inspection When A Signature Update Is Loaded While Signature Compilation Is In Progress

Last Modified: Sep 02, 2026

Affected Product(s):
BIG-IP TMOS(all modules)

Fixed In:
17.5.1.9

Opened: Apr 21, 2026

Severity: 3-Major

Symptoms

When a second IPS signature update is loaded while the IPS daemon is still compiling signatures from a previous update, traffic that matches signature-based inspection rules passes through without being inspected

Impact

Traffic that would typically be blocked or rejected by signature-based IPS rules goes uninspected

Conditions

A virtual server has an IPS profile that includes signature-based inspection rules attached to it A signature update is loaded. While the profile status shows "Signature compilation...", a second signature update is loaded before the first compilation completes

Workaround

Before loading a new signature update, verify that all IPS profiles have reached Ready status

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips