Bug ID 2139965: AFM DNS DOS logging protocol_dns_dos_nxdomain_field_attack_name()

Last Modified: Dec 17, 2025

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
17.5.1.3

Opened: Oct 26, 2025

Severity: 2-Critical

Symptoms

Tmm crashes are observed for specific configurations where log_data_autodos or related settings (log_data_dos_nxdomain) are used. The crash occurs for every 1 to 2 hours after DNS NXDOMAIN learning begins. Logs from the crash may indicate issues in protocol_dns_dos_nxdomain_field_attack_name() function or references to log_data_dos_nxdomain. DNS NXDOMAIN learning fails entirely and does not function as expected, preventing proper logging or learning.

Impact

Traffic disrupted while tmm restarts.

Conditions

This can occur 1-2 hours after enabling log_data_autodos or log_data_dos_nxdomain

Workaround

Set the dos.dnsnxdomain.learnperiod parameter to a larger value that is more comfortable for the situation.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips