Bug ID 644822: FastL4 virtual server with enabled loose-init option works differently with/without AFM provisioned

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1

Fixed In:
12.1.3.2

Opened: Feb 14, 2017

Severity: 2-Critical

Related Article: K19245372

Symptoms

If AFM provisioned, a FastL4 virtual server with enabled loose-init option drops all RST packets that do not relate to any existing flows. This behavior does not match the BIG-IP behavior when AFM is not provisioned.

Impact

RST packets that do not relate to any existing flows are dropped, while they should not be dropped if the loose-init option enabled.

Conditions

AFM provisioned. -- FastL4 virtual server. -- Loose-init option enabled.

Workaround

No workaround.

Fix Information

This issue is resolved on BIG-IP v13.1.0 and later with the fix for bug 629674 https://cdn.f5.com/product/bugtracker/ID629674.html. In these releases, FastL4 virtual servers with the loose-init option enabled will forward RST packets.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips