Bug ID 681673: tmsh modify FDB command permits multicast MAC addresses, which produces unexpected results

Last Modified: May 14, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1

Fixed In:
14.0.0, 13.1.1.2

Opened: Sep 05, 2017
Severity: 3-Major

Symptoms

TMSH does not block modify FDB commands that add a multicast MAC addresses.

Impact

There is not enough information to map the outgoing MAC address to a multi-cast group, and therefore it gets a default entry added that has no ports mapped. The result is that the frame will not go out the interface indicated in the tmsh command yet no warning is provided.

Conditions

This occurs when the following is configured using tmsh commands when the mac-address is multicast: fdb vlan <vlan> records add {<mac-address> {interface <slot>/<port>}}.

Workaround

None.

Fix Information

TMSH modify FDB command is no longer permitted to add multicast MAC addresses, so this issue no longer occurs.

Behavior Change