Bug ID 868209: Transparent vlan-group with standard virtual-server does L2 forwarding instead of pool selection

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP None(all modules)

Known Affected Versions:
14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2

Fixed In:
16.1.0, 15.1.2.1, 14.1.4

Opened: Jan 10, 2020

Severity: 3-Major

Symptoms

When BIG-IP is configured with transparent vlan-group and traffic is matching a standard or fastl4 virtual-server and traffic hitting BIG-IP does not have a destination MAC address that belongs to BIG-IP - traffic will be L2 forwarded and pool member selection will not happen. This defect will also cause active FTP data connections over vlan-group to fail.

Impact

Server-side connections will fail.

Conditions

All conditions must be met: - Traffic over transparent vlan-group. - Standard or fastl4 virtual-server. - Traffic has a destination MAC address that does not belong to BIG-IP. OR - Standard virtual server with FTP profile is configured. - Active FTP session is in use. - Traffic flows over vlan-group.

Workaround

Use opaque vlan-group instead. OR disable db variable connection.vgl2transparent (15.0+)

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips