Bug ID 497742: Some TCP re-transmits on translucent vlangroup skip bit-flip on source MAC address

Last Modified: Feb 13, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.5.1 HF1, 11.5.1 HF10, 11.5.1 HF11, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.2, 11.5.2 HF1, 11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4, 11.6.0 HF5

Fixed In:
12.0.0, 11.6.0 HF6, 11.5.3, 11.4.1 HF9

Opened: Dec 19, 2014
Severity: 3-Major
Related AskF5 Article:
K16296

Symptoms

Some packets re-transmitted as part of a full-proxy, non-SNAT'd TCP virtual server on a translucent-mode vlangroup do not correctly have the translucent-mode bit-flip applied.

Impact

Egressing traffic with the source-MAC of another host can potentially lead to traffic loops.

Conditions

This occurs with a translucent vlangroup and full virtual server with no SNAT.

Workaround

Enable SNAT on the virtual server.

Fix Information

All TCP re-transmits have the proper source MAC address.

Behavior Change