Bug ID 580862: Policy disabled after enabled with apply-policy via REST, asm-sync removal fixes

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5

Fixed In:
13.0.0, 12.1.3.6

Opened: Mar 16, 2016

Severity: 3-Major

Symptoms

After the Apply-policy task completes successfully, there is an LTM incremental sync back from the peer unit and the policy is deactivated.

Impact

ASM policy is erroneously deactivated several seconds after it has been activated via the Apply-policy task.

Conditions

High availability (HA) configuration with an auto-sync failover group with ASM sync enabled.

Workaround

Temporarily disable ASM sync on the device group.

Fix Information

This release fixes the Apply-policy task so that there is no erroneous deactivation after it has completed.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips