Bug ID 496197: iRule in v10 allows overriding "down user-disabled" node to receive new requests

Last Modified: Nov 07, 2022

Bug Tracker

Affected Product:  See more info
BIG-IP Install/Upgrade, LTM(all modules)

Known Affected Versions:
10.2.4, 11.4.1, 11.5.0, 11.5.1, 11.5.1 HF1, 11.5.1 HF10, 11.5.1 HF11, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.10, 11.5.2, 11.5.2 HF1, 11.5.3, 11.5.3 HF1, 11.5.3 HF2, 11.5.4, 11.5.4 HF1, 11.5.4 HF2, 11.5.4 HF3, 11.5.4 HF4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9

Opened: Dec 12, 2014
Severity: 3-Major

Symptoms

When pool member is forced-down and has a irule pool command, the command can still direct the requests to the node. After upgrading to v11.x it resets the connection saying "Pool member unavailable".

Impact

Traffic could inadvertantly be directed to a forced down pool member.

Conditions

Disable the pool member then select it from an iRule

Workaround

None

Fix Information

None

Behavior Change