Bug ID 688841: Configuration validation does not catch enabling DoS Application Security Behavioral DoS from Local Traffic Policy rule

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP AFM, ASM(all modules)

Known Affected Versions:
13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1

Opened: Oct 15, 2017

Severity: 4-Minor

Symptoms

You can create a DoS profile that enables Application Security Behavioral Detection and Mitigation and invoke that DoS profile from a Local Traffic Policy rule via the Enable L7DoS Action. However, the Application Security Behavioral Detection and Mitigation setting will be ignored. Only the default DoS profile attached directly to the Virtual Server can successfully enable Application Security Behavioral Detection and Mitigation.

Impact

The system silently ignores attempts to enable DoS Application Security Behavioral Detection and Mitigation.

Conditions

-- DoS policy that enables Application Security Behavioral Detection and Mitigation. -- Local Traffic policy rule that invokes that DoS policy.

Workaround

Enable DoS Application Security Behavioral Detection and Mitigation in a DoS profile attached directly to the Virtual Server. Note: Although you can invoke any number of other DoS profiles via Local Traffic policy rules, they cannot successfully enable DoS Application Security Behavioral Detection and Mitigation.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips