Bug ID 1587225: IPv6 HTTP explicit proxy virtual-server might fail to process connections from certain IPv6 clients

Last Modified: Jun 19, 2025

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4, 15.1.10.5, 15.1.10.6

Opened: May 20, 2024

Severity: 3-Major

Symptoms

Under certain conditions, the BIG-IP will use a deterministic algorithm to translate a source IPv6 client to an IPv4 address. Depending on the IPv6 address, it is possible the BIG-IP translates it to a multicast IPv4 address. When this happens, the forwarding virtual-server used to process the HTTP explicit proxy traffic might drop such connections due to having a multicast source.

Impact

Connections from certain IPv6 clients will fail

Conditions

-- IPv6 virtual server with HTTP explicit proxy profile -- Source-address-translation on the IPv6 HTTP explicit proxy virtual-server with any option configured other than a SNAT pool consisting of IPv4-only IPs -- When resolving the destination hostname, DNS returns an A record (IPv4) -- Forwarding virtual server with standard type

Workaround

-- On the IPv6 virtual-server with http explicit proxy profile, use a SNAT pool with IPv4 addresses only -- Use FastL4 on the forwarding virtual-server (instead of 'standard' type)

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips