Bug ID 2386237: Traffic-matching-criteria with no route-domain specified fails to match traffic in non-default route-domain partition

Last Modified: Jul 28, 2026

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
17.1.0, 17.1.0.1, 17.1.0.2, 17.1.0.3, 17.1.1, 17.1.1.1, 17.1.1.2, 17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1, 17.1.2.2, 17.1.3, 17.1.3.1, 17.1.3.2, 17.1.3.4, 17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4, 17.5.1.5, 17.5.1.6, 17.5.1.8, 21.0.0, 21.0.0.1, 21.0.0.2, 21.0.0.3, 21.1.0, 21.1.0.1

Opened: Jul 09, 2026

Severity: 3-Major

Symptoms

In a partition that uses a non-default route domain, a traffic-matching criteria object created without specifying an explicit route domain (for example, through the GUI or by using the 'load sys config' command) builds its virtual address and listener in route domain 0. As a result, traffic within the partition's route domain will not match the listener. Please note that the TMSH workaround needs to be reapplied on each device after every configuration synchronization or reload

Impact

Traffic fails to match the virtual server. The TMSH workaround does not survive config-sync or config reload

Conditions

- A partition with a non-default route domain is configured - A traffic-matching-criteria object is created without an explicit route-domain (including via the GUI or config load)

Workaround

When creating the traffic-matching-criteria object via TMSH, specify the route-domain explicitly. See K94024302 for steps

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips