Bug ID 476179: Brute Force end attack operation mode reported as blocking while it was actually in transparent mode

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
11.5.1, 11.5.1 HF1, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3

Fixed In:
12.0.0, 11.6.0 HF4, 11.5.1 HF6

Opened: Aug 20, 2014

Severity: 3-Major

Symptoms

When the Brute-Force attack_status ended log message appear - the operation mode changed to Blocking even though he has set it as Alarm on the configuration.

Impact

False reporting during Transparent Brute Force attack.

Conditions

When brute force configured to work in Transparent mode

Workaround

N/A

Fix Information

Brute force reporting: The brute force reported operation mode (Transparent or Blocking) is now the same when the attack starts and ends. Previously, sometimes the system would change the operation mode logged when the attack ended.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips