Last Modified: Sep 02, 2026
Affected Product(s):
BIG-IP TMOS
Known Affected Versions:
17.1.3.5, 21.1.0.2
Opened: Aug 17, 2026 Severity: 3-Major
In a Velocity tenant, the tenant creates FDB entries on the host that inform the host about VLAN+MAC pairings. If a tenant has multiple VLANs and different MAC addresses assigned to each VLAN, and is rebooted or upgraded, there is a chance that MAC address + VLAN mappings change. K50122514 contains details describing MAC address changes after an upgrade, which is expected behavior Example showing invalid FDB entries that do not match the current VLAN+MAC pairings on the tenant [root@localhost:Active:Standalone] config # tmsh show net vlan | grep -e Mac -e Vlan | paste - - Net::Vlan: VLAN43 Mac Address (True) 00:94:a1:6a:d5:60 Net::Vlan: VLAN44 Mac Address (True) 00:94:a1:6a:d5:61 Net::Vlan: VLAN45 Mac Address (True) 00:94:a1:6a:d5:62 R10900-R84-S35# show fdb SUB MOD NDI MAC ADDRESS VLAN TAG TYPE VLAN TAG TYPE VID ENTRY TYPE OWNER ID AGE ID SVC VTC SEP DMS DID CMDS MIRRORING INTERFACE ------------------------------------------------------------------------------------------------------------------------------------------------------------------- 00:94:a1:6a:d5:62 43 tag_type_vid 43 tag_type_vid 43 L2-LISTENER repro-tenant-2 0 - 4095 14 - - - - 1 - - <----- WRONG 00:94:a1:6a:d5:60 43 tag_type_vid 43 tag_type_vid 43 L2-LISTENER repro-tenant-2 0 - 4095 14 - - - - 1 - - 00:94:a1:6a:d5:60 44 tag_type_vid 44 tag_type_vid 44 L2-LISTENER repro-tenant-2 0 - 4095 14 - - - - 1 - - <----- WRONG 00:94:a1:6a:d5:61 44 tag_type_vid 44 tag_type_vid 44 L2-LISTENER repro-tenant-2 0 - 4095 14 - - - - 1 - - 00:94:a1:6a:d5:61 45 tag_type_vid 45 tag_type_vid 45 L2-LISTENER repro-tenant-2 0 - 4095 14 - - - - 1 - - <----- WRONG 00:94:a1:6a:d5:62 45 tag_type_vid 45 tag_type_vid 45 L2-LISTENER repro-tenant-2 0 - 4095 14 - - - - 1 - -
Traffic disruption. Traffic returning to the tenant on the wrong VLAN
A Velocity tenant deployed with a MAC block size > 1 VLAN > MAC pairings that change after an upgrade
Either delete the old invalid FDB entries manually in F5OS, reboot the F5OS Appliance or blade to clear the entries
None