Bug ID 701299: Protocol Inspection: config validation for GTP Compliance Check does not catch inclusion of APN in both disallowed_apns and allowed_apns

Last Modified: Nov 07, 2022

Bug Tracker

Affected Product:  See more info
BIG-IP AFM(all modules)

Known Affected Versions:
14.0.0,,,,,, 14.0.1,

Opened: Jan 10, 2018
Severity: 4-Minor


A user can include the same APN in the GTP compliance checks disallowed_apns and allowed_apns.


A logically inconsistent configuration is validated. The resultant behavior might be unexpected. If an APN is on the "Disallowed APNs" list, traffic from matching APNs will be dropped even if they are on the "Allowed APNs" list.


Protocol Inspection configured to enable GTP compliance checks with a given APN specified in both the "Allowed APNs" and "Disallowed APNs" lists.


Review configuration manually and catch these configuration conflicts.

Fix Information


Behavior Change