Last Modified: Mar 03, 2026
Affected Product(s):
BIG-IP AFM
Known Affected Versions:
17.1.3, 17.1.3.1
Opened: Feb 24, 2026 Severity: 3-Major
IPS violation ID10008 drops DNS-over-TCP responses larger of 6948 bytes
DNS traffic blocked
DNS responses with large ADDITIONAL sections (multiple NS records + DNSSEC keys) exceeding MAX_DNSSEC_SIZE byte IPS parsing limit
Modify ID10008 action from "drop" to required in IPS profile
None