Bug ID 420315: Brute force attack drop reports are about 10% less than actual

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
11.2.1, 11.3.0, 11.4.0

Fixed In:
11.5.0, 11.4.0 HF3, 11.3.0 HF8, 11.2.1 HF8

Opened: May 01, 2013

Severity: 3-Major

Related Article: K72944100

Symptoms

The drop reports are not accurate in brute force. The drops from the last seconds of the attack are not reported.

Impact

Not accurate staticts reporting in GUI of rejected connections for brute force attack.

Conditions

Customer encountered on their own and found the numbers of Rejected Connections and dropped_requests don't match the number of actually dropped requests on a client.

Workaround

This issue has no workaround at this time.

Fix Information

The system now reports brute force drops even from the last seconds of an attack.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips