Bug ID 1586657: [Win][IPv6]VPN connection fails with Edge client 7.2.4.6 with error "Network is vulnerable"

Last Modified: Apr 28, 2025

Affected Product(s):
APM-Clients APM(all modules)

Known Affected Versions:
7.2.4.6, 7.2.4.7

Fixed In:
7.2.5, 7.2.4.8

Opened: May 17, 2024

Severity: 2-Critical

Related Article: go/K000138683

Symptoms

VPN fails with a popup saying Network is vulnerable You may see below logs in f5report Error 2024-05-15 15:02:03:917 HOST \m_VerifyPreConfigInfo.cpp, verifyPreConfigLocalAndServerIpInformation, ALERT: Provided Resolved IP is NOT a Valid APM Server IP, seems the virtual server IP is spoofed Error 2024-05-15 15:02:03:917 HOST CHostCtrl::Load, CHostCtrl::Load, The connected network is vulnerable for tunnel crack attack due to server IP attack, please change the network. Stopping the VPN connection initioalization

Impact

Unable to establish VPN with IPv6 Virtual server.

Conditions

- IPv6 Virtual server

Workaround

Install EHF with ID1505789. By default this EHF disables "ServerIPCheck" so this issue is not observed.

Fix Information

Fixed the issue where VPN connection fails when connecting to IPv6 Virtual Server with Windows VPN Clients version 7.2.4.6 or above displaying a network vulnerable dialog box.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips