Bug ID 967561: IPsec ISAKMP IKEv2 negotiation may cause TMM to core

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6

Opened: Nov 25, 2020

Severity: 4-Minor

Symptoms

When an IPsec tunnel's traffic-selectors are misconfigured, tmm may crash.

Impact

Traffic disrupted while tmm restarts.

Conditions

Currently the conditions are uncertain, but may involve: -- Creating a traffic-selector that requires the BIG-IP to narrow the selector during negotiation or -- A tunnel that has multiple traffic-selectors where one of the selectors is (incorrectly) a mirror image of the correct selector.

Workaround

Ensure that traffic-selectors match the remote peer's configuration.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips