Last Modified: Jan 29, 2019
See more info
Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 188.8.131.52, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 12.1.4, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 220.127.116.11, 13.1.1, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52
Opened: Apr 11, 2018
When the self IP has a firewall rule to reject ICMP unreachable, the system will be sent from active to standby and not from standby to active. This is correct behavior, but v13.x might show ICMP unreachable messages sent from standby to active along with those from active to standby.
No functional impact. ICMP unreachable messages not showing has no effect on BIG-IP system functionality. Note: If there is a firewall to block traffic on self IPs, but still want ICMP unreachable messages, that configuration is not valid, and HA will not work.
-- AFM firewall rule is applied to the self IP as reject ICMP unreachable messages. -- Active/standby high availability (HA) cluster.
There is no workaround.
In v12.x, with AFM in reject mode and self IP rule is 'reject'. The reject ICMP unreachable messages are observed only from active to standby. In v13.x, ICMP unreachable messages are observed in both directions, active to standby and standby to active.