Bug ID 987605: DDoS: ICMP attacks are not hardware-mitigated

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1

Fixed In:
15.1.4

Opened: Jan 27, 2021

Severity: 3-Major

Symptoms

ICMP/Fragments attacks against a virtual server with a DOS profile are not mitigated by hardware.

Impact

ICMP/Fragments attacks mitigation/detection is handled in software. A large volume of attack traffic can spike the tmm CPU.

Conditions

ICMP/Fragments attacks mitigation/detection is configured on a virtual system with neuron-capable hardware.

Workaround

None

Fix Information

Until the hardware is fixed, the software uses the SPVA in hardware to mitigate these attacks.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips