Last Modified: Aug 27, 2026
Affected Product(s):
BIG-IP APM
Known Affected Versions:
14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 14.1.5.1, 14.1.5.2, 14.1.5.3, 14.1.5.4, 14.1.5.6, 17.5.1.8
Opened: Dec 29, 2020 Severity: 3-Major
When AD Auth has "Cross Domain Support" enabled and the Logon Page has "Split domain from full Username" enabled, each authentication attempt sends two AS-REQ messages to the KDC instead of one. This causes the KDC's failed-login counter to increment twice per attempt, potentially locking out user accounts before the configured AD account lockout threshold is reached.
Users may be locked out of Active Directory after fewer failed attempts than expected. The "Max Logon Attempts Allowed" setting on the BIG-IP effectively consumes double the KDC lockout budget.
AD Auth agent with Cross Domain Support enabled; Logon Page with "Split domain from full Username" enabled; user logs in with domain\username format where domain matches the configured AD domain.
None
None