Bug ID 837269: Processing ICMP unreachable packets causes FWNAT/CGNAT persistence issues with UDP traffic

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
14.1.0,,,,,, 14.1.2,,,,,,,, 15.0.0, 15.0.1,,,,

Fixed In:
16.0.0, 15.1.0,

Opened: Oct 10, 2019

Severity: 3-Major


When hosts send ICMP unreachable error messages and processed by the BIG-IP system, subsequent good UDP packets do not get the persistence LSN translation address.


LSN persistence issues. UDP packets from the same client IP address may not get the same translation address every time, even though there exists a persistence entry in the table


-- Virtual server with FW NAT or CGNAT configuration to accept UDP traffic. -- Client or/and server randomly sends ICMP unreachable messages.



Fix Information

Processing ICMP unreachable packets no longer causes FWNAT/CGNAT persistence issues with UDP traffic.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips