Last Modified: Jan 07, 2020
See more info
BIG-IP Install/Upgrade, LTM
Known Affected Versions:
14.1.0, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 220.127.116.11, 14.1.2, 15.0.0, 15.0.1, 15.1.0
Opened: Mar 04, 2019
If firewall is configured on the management port with an ICMP rule, after upgrading to v14.1.x or later, the ICMP rule does not work.
ICMP packets cannot be blocked with a firewall rule to drop on management port. ICMP packets are allowed from the management port.
-- Firewall is configured on the management port. -- Firewall is configured with an ICMP rule to block.
Run the following commands after upgrading to v14.1.x or later from earlier versions. # /sbin/iptables -N id760355 # /sbin/iptables -I INPUT 1 -j id760355 # /sbin/iptables -A id760355 -i mgmt -p icmp --icmp-type 8 -s 172.28.4.32 -j DROP
ICMP firewall rule has been moved from the f5-required to f5-default.