Bug ID 980117: Dynamic template HA: Missing ike-sa's are seen on standby BIG-IP when Initiator is placed behind NAT

Last Modified: Nov 22, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP TMOS(all modules)

Fixed In:
16.1.0

Opened: Jan 07, 2021
Severity: 2-Critical

Symptoms

Missing ike-sa's are seen on standby BIG-IP when Initiator is placed behind NAT

Impact

IKE-SA's are not propagated to the standby device.

Conditions

-- Initiator is behind a NAT. -- High availability (HA) pair between BIG-IP. -- Dynamic template configuration on BIG-IP and NAT traversal is 'ON'. -- IPsec tunnel client traffic

Workaround

None

Fix Information

None

Behavior Change