Bug ID 680856: IPsec config via REST scripts may require post-definition touch of both policy and traffic selector

Last Modified: Oct 16, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
12.1.2, 12.1.3,,,,,, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0,,,,,,,,, 13.1.1,,

Fixed In:

Opened: Aug 30, 2017

Severity: 4-Minor


A new IPsec tunnel may not work after being configured over REST. While the configuration is correct, a log message similar to the following may appear in ipsec.log (IKEv2 example): info tmm[24203]: 017c0000 [0.0] [IKE] [INTERNAL_ERR]: selector index (/Common/Peer_172.16.4.1) does not have corresponding policy


The newly configured IPsec tunnel does not start.


A new IPsec tunnel is configured over REST.


The following methods cause the traffic-selector and ipsec-policy to be correctly related to one another: -- Restart tmm. -- Change the configuration, for example the Description field, of both the policy and the traffic selector. This may also be done using REST.

Fix Information

A traffic selector can no longer use a deleted policy by name, and if recreated after deletion, the policy is correctly constructed.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips