Bug ID 929909: TCP Packets are not dropped in IP Intelligence

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 15.1.4, 15.1.4.1, 15.1.5, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2, 16.1.0, 16.1.1, 16.1.2, 16.1.2.1

Fixed In:
17.0.0, 16.1.2.2, 15.1.5.1

Opened: Jul 22, 2020

Severity: 3-Major

Symptoms

When an IP address is added to IP Intelligence under Denial-Of_service Category at a global level, and a TCP flood with that IP address occurs, IP Intelligence does not drop those packets

Impact

When adding an IP address to an IP Intelligence category, UDP traffic from that IP address is dropped, but TCP traffic is not dropped.

Conditions

TCP traffic on BIG-IP with IP Intelligence enabled and provisioned

Workaround

None

Fix Information

When adding an IP address to an IP Intelligence category, both TCP and UDP traffic from that IP address is dropped.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips