Bug ID 999021: IPsec IKEv1 tunnels fail after a config sync from Standby to Active

Last Modified: Mar 26, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP TMOS(all modules)

Known Affected Versions:
16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1

Opened: Mar 03, 2021
Severity: 3-Major

Symptoms

When racoon (the IKEv1 daemon) sees a tunnel config change, which occurs due to a config sync from the standby device, the change causes tmm and racoon to have conflicting views on the state of that tunnel. If the IKEv1 tunnel is up at the time of the config change, tmm fails to restart the tunnel.

Impact

IPsec IKEv1 tunnels fail and do not start again.

Conditions

-- IPsec IKEv1 tunnel in use. -- Changes made to IPsec IKEv1 tunnel on the Standby BIG-IP device, which are then sync'd to the Active BIG-IP device. -- And/or a full config sync from the Standby to Active BIG-IP system.

Workaround

-- Do not make changes to IPsec IKEv1 tunnels on the Standby device. -- Avoid full syncs from Standby to Active. How to recover when the problem occurs: -- Disable the affected ike-peer and re-enable it.

Fix Information

None

Behavior Change