Last Modified: May 29, 2024
Affected Product(s):
BIG-IP (all modules)
Known Affected Versions:
14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2
Fixed In:
16.1.0, 15.1.2.1, 14.1.4
Opened: Jan 10, 2020 Severity: 3-Major
When BIG-IP is configured with transparent vlan-group and traffic is matching a standard or fastl4 virtual-server and traffic hitting BIG-IP does not have a destination MAC address that belongs to BIG-IP - traffic will be L2 forwarded and pool member selection will not happen. This defect will also cause active FTP data connections over vlan-group to fail.
Server-side connections will fail.
All conditions must be met: - Traffic over transparent vlan-group. - Standard or fastl4 virtual-server. - Traffic has a destination MAC address that does not belong to BIG-IP. OR - Standard virtual server with FTP profile is configured. - Active FTP session is in use. - Traffic flows over vlan-group.
Use opaque vlan-group instead. OR disable db variable connection.vgl2transparent (15.0+)
None