Bug ID 2450009: SSL handshake failures between high availability peers when ConfigSync uses the management IP

Last Modified: Sep 01, 2026

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
17.1.3.4, 17.5.1.8, 21.0.0.3, 21.1.0.1

Opened: Aug 05, 2026

Severity: 3-Major

Symptoms

SSL handshake failures are logged between the peer address and an internal TMM address, and peer certificate verification errors referring to a self-signed certificate appear in the logs. The connection to the CMI peer is subsequently removed

Impact

Configuration synchronization between high availability peers fails, causing the peer connection to drop. As a result, configuration changes are not synchronized, and device group membership may seem disconnected until the issue is resolved

Conditions

BIG-IP systems in a high availability configuration where ConfigSync is configured to use the management IP address on both devices (the database variable that allows ConfigSync over the management address is enabled)

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips