Bug ID 879829: HA daemon sod cannot bind to ports numbered lower than 1024

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
13.1.0,,,,,,,,, 13.1.1,,,,, 13.1.3,,,,,,, 13.1.4,, 13.1.5,, 14.0.0,,,,,, 14.0.1,, 14.1.0,,,,,, 14.1.2,,,,,,,,, 14.1.3,, 15.0.0, 15.0.1,,,,, 15.1.0,,,,,, 15.1.1, 15.1.2,, 16.0.0,, 16.0.1,

Fixed In:
16.1.0,, 15.1.3, 14.1.4

Opened: Feb 11, 2020

Severity: 3-Major


If the network high availability (HA) daemon sod is configured to use a port number that is lower than 1024, the binding fails with a permission-denied error. This affects binding to ports on both management and self IP addresses. Example log messages: /var/log/ltm err sod[2922]: 010c003b:3: bind fails on recv_sock_fd addr port 1023 error Permission denied. notice sod[2992]: 010c0078:5: Not listening for unicast failover packets on address port 1023. /var/log/auditd/audit.log type=AVC msg=audit(1578067041.047:17108): avc: denied { net_bind_service } for pid=2922 comm="sod" capability=10 scontext=system_u:system_r:f5sod_t:s0 tcontext=system_u:system_r:f5sod_t:s0 tclass=capability


A network high availability (HA) connection configured to use a port number lower than 1024 on an affected version does not function.


-- high availability (HA) daemon sod is configured to use a port lower than 1024 for network high availability (HA) operations. -- Version 13.1.0 or later.


Change the port number to 1024 or higher. Note: UDP port 1026 is the default.

Fix Information


Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips