Last Modified: Feb 03, 2026
Affected Product(s):
BIG-IP AVR
Known Affected Versions:
17.1.3, 17.1.3.1
Opened: Jan 29, 2026 Severity: 3-Major
When both "Insert X-Forwarded-For" and "Accept XFF" options are enabled in the HTTP profile, the AVR function dosl7_get_client_ip fails to extract the X-Forwarded-For header.
Bot Defense profiles do not honor the true client IP from X-Forwarded-For headers
"Insert X-Forwarded-For" and "Accept XFF" should be enabled in the HTTP profile.
AVRD restart - bigstart restart avrd.
None