Bug ID 749761: AFM Policy with Send to Virtual and TMM crash in a specific scenario

Last Modified: Sep 14, 2023

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 13.1.5, 13.1.5.1, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 14.1.5.1, 14.1.5.2, 14.1.5.3, 14.1.5.4, 14.1.5.6

Fixed In:
15.0.0

Opened: Nov 14, 2018

Severity: 3-Major

Symptoms

TMM restart in a specific scenario when AFM Policy is configured in multiple contexts (Global, Route Domain, Virtual Server), with Log Translations enabled, and Send-To-VS feature configured in at least one of the rules in the Security Policy.

Impact

TMM restart causes service disruption. Traffic disrupted while tmm restarts.

Conditions

-- When using Firewall ACL Policy in more than one context, i.e., more than one of the following context has ACL Security Policy applied: + Global Context + Route Domain + Virtual Server Context -- Send To Virtual Server is configured on any Rule on the Security policy. -- Traffic matching a Rule (with logging enabled) in more than one context. -- AFM Security Logging Profile has log Translation Field Enabled.

Workaround

Disable Logging of Translation Fields in Security Logging Profile.

Fix Information

Invalid memory access when ACL classification is done second time, to support Send to Virtual feature in a specific scenario.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips