Loading...
Loading...
The BIG-IP system erroneously performs a SNAT translation after the SNAT translation address has been disabled. As a result of this issue, you may encounter the following symptom: A network trace capturing the affected traffic on a BIG-IP system shows traffic continues to egress the BIG-IP system using the disabled SNAT translation address.
Traffic egresses the BIG-IP system with the disabled SNAT translation address.
This issue occurs when the following condition is met: A SNAT translation address is configured, but disabled.
To work around this issue, you must delete the affected SNAT configuration instead of disabling it. To do so, perform the following procedure: Impact of workaround: Deleting the affected SNAT configuration removes it entirely from the BIG-IP configuration. If you require the SNAT configuration later, you must recreate it manually. BIG-IP 11.x/12.x 1. Log in to the tmsh utility. 2. Delete the affected SNAT configuration by entering the following command: delete /ltm snat <affected SNAT name>. For example, to delete the test-315765 SNAT configuration, you would enter the following command: delete /ltm snat test-315765. 3. Save the modified configuration by entering the following command: save /sys config BIG-IP 9.x through 10.x 1. Log in to the command line. 2. Delete the affected SNAT configuration by entering the following command: bigpipe snat <affected SNAT name> delete. For example, to delete the test-315765 SNAT configuration, you would enter the following command: bigpipe snat test-315765 delete. 3. Save the modified configuration by entering the following command: bigpipe save all.
None
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.