Last Modified: Sep 09, 2026
Affected Product(s):
BIG-IP SSLO
Known Affected Versions:
17.1.0, 17.1.0.1, 17.1.0.2, 17.1.0.3, 17.1.1, 17.1.1.1, 17.1.1.2, 17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1, 17.1.2.2, 17.1.3, 17.1.3.1, 17.1.3.2, 17.1.3.4, 17.1.3.5, 17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4, 17.5.1.5, 17.5.1.6, 17.5.1.8, 17.5.1.9, 21.1.0, 21.1.0.1, 21.1.0.2
Opened: Aug 20, 2026 Severity: 4-Minor
In the SSL Orchestrator Traffic Summary log message, the policy-rule portion prints individual policy items (like Category Lookup) instead of the policy rule the item is running under
Traffic Summary log may be misinterpreted, and it seems that an unknown or unauthorized policy rule is being applied The log does not clearly distinguish between: The final matched top-level policy rule; and An internal policy node reached before the flow failed or timed out This all creates ambiguity during troubleshooting and log analysis
The SSL Orchestrator traffic summary log is configured to show up (SSL Orchestrator log levels are set to info), and the flow corresponding to the log message did not complete successfully
While there is no workaround to have the policy rule actually print the rule, you can look at the APM Per Request Policy to determine which policy rule applies to the policy item that was logged
None