Last Modified: Jul 28, 2026
Affected Product(s):
BIG-IP SSLO
Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4, 17.5.1.5, 17.5.1.6
Fixed In:
17.5.1.8
Opened: May 21, 2025 Severity: 3-Major
When a persistence profile (for example, source address affinity) is attached to an SSLO inspection service entry virtual server, traffic from the same client is not always sent to the same pool member or inspection device. Clients get distributed across different service pool members instead of sticking to one.
Client traffic is not consistently routed to the same inspection service.
This issue occurs on F5OS based physical appliances (for example, VELOS or rSeries hardware). SSLO topology must have an inspection service pool with more than one member and a persistence profile attached to the inspection service entry virtual server.
None.
This fix ensures that clients are consistently sent to the same inspection service pool member when a persistence profile is attached to the SSLO inspection service entry virtual server. This is supported for all services except ICAP.