Bug ID 649933: Fragmented RADIUS messages may be dropped

Last Modified: Aug 19, 2026

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
11.5.4, 11.5.4 hf1, 11.5.4 hf2, 11.5.4 hf3, 11.5.4 hf4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.1, 11.6.1 hf1, 11.6.1 hf2, 12.1.0, 12.1.0 hf1, 12.1.0 hf2, 12.1.1, 12.1.1 hf1, 12.1.1 hf2, 12.1.2, 12.1.2 hf1, 12.1.2 hf2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6, 13.0.0, 13.0.0 hf1, 13.0.0 hf2, 13.0.0 hf3, 13.0.1

Fixed In:
13.1.0, 11.6.2

Opened: Mar 09, 2017

Severity: 3-Major

Symptoms

Large RADIUS messages may be dropped when processed by iRules.

Impact

The RADIUS message will be dropped, and an error will be logged that resembles: Illegal argument (line 1) (line 1) invoked from within "RADIUS::avp 61 "integer""

Conditions

This occurs when a RADIUS message that exceeds 2048 bytes is processed by an iRule containing the RADIUS::avp command.

Workaround

Remove RADIUS::avp commands from iRules processing large messages, or ensure that no RADIUS client or server will send large messages.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips