Bug ID 457327: UDP virtual server with Datagram LB ignores ICMP Fragmentation Needed messages

Last Modified: Oct 17, 2023

Affected Product(s):
BIG-IP GTM, LTM(all modules)

Known Affected Versions:
11.2.1, 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 13.1.5, 13.1.5.1

Opened: Apr 15, 2014

Severity: 3-Major

Related Article: K16160

Symptoms

Received ICMP Fragmentation Needed messages are not honored by Standard Virtual Servers using a UDP profile with Datagram LB enabled.

Impact

- Large DNS lookups from lower MTU networks might fail. Note: Most DNS request/responses should not have this problem but DNSSEC may be more exposed. - Services which depend on very large UDP datagrams may fail when used with Datagram LB.

Conditions

- Standard Virtual Server with UDP profile with Datagram LB enabled. - BIG-IP sends a datagram exceeding the Path MTU to the destination. - BIG-IP receives an ICMP Fragmentation Needed message.

Workaround

Disable PMTU discovery by running the command: tmsh modify sys db tm.pathmtudiscovery value disable. (Note: This is a global setting and impacts all connections to the BIG-IP system.) Now, outgoing packets do not have the DONT FRAG bit set, and upstream routers can fragment large packets (this is useful only for IPv4). If the issue is caused by the immediate upstream router, set MTU on BIG-IP system VLAN to match the lower MTU. This prevents the BIG-IP system from sending large packets.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips