Last Modified: Sep 12, 2025
Affected Product(s):
BIG-IP APM
Known Affected Versions:
17.1.1, 17.1.1.1, 17.1.1.2, 17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1, 17.1.2.2
Opened: Jul 23, 2025 Severity: 3-Major
AAA LDAP pool-based configuration in APM resets the Priority Group Activation (PGA) setting to the default after any update to AAA LDAP configuration. Manual changes to PGA (e.g., disabling it) are overwritten during AAA updates in the APM UI.
-- Custom settings for Priority Group Activation are not persistent and are overwritten during APM updates. -- Load balancing behavior may not work as intended if PGA is reset unexpectedly.
-- AAA LDAP is configured in APM with the "Use Pool" option enabled. -- Priority Group Activation on the auto-generated pool is manually set to "Disabled" via Local Traffic > Pools. -- Any subsequent update to the AAA LDAP configuration in APM resets the Priority Group Activation setting back to "Less than 1 Available Member(s)".
Manually update Priority Group Activation settings in the auto-generated pool via Local Traffic > Pools after each AAA LDAP configuration update in APM. Disable Priority Group Activation immediately after updating any AAA LDAP configuration values in APM.
None