Bug ID 465415: AFM DoS has not been tested with QinQ tunnels

Last Modified: Apr 10, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP AFM(all modules)

Known Affected Versions:
11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4, 11.6.0 HF5, 11.6.0 HF6, 11.6.0 HF7, 11.6.0 HF8, 11.6.1, 11.6.1 HF1, 11.6.1 HF2, 11.6.2, 11.6.2 HF1, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 12.0.0, 12.0.0 HF1, 12.0.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1

Opened: Jun 03, 2014
Severity: 4-Minor

Symptoms

AFM DoS has not been tested or qualified with QinQ tunnels. One issue is that HW DoS detection may trigger false positives for the "L2 length >> IP length" DoS vector. SW DoS detection handles this case correctly.

Impact

AFM DoS and QinQ tunnels might not work well together.

Conditions

QinQ and AFM DoS on a platform that supports HW DoS detection.

Workaround

Disabling HW DoS detection may permit successful handling of QinQ tunnel traffic.

Fix Information

None

Behavior Change