Loading...
Loading...
As a result of this issue, you may encounter the following symptoms: - Unexplained authentication session failures - NTLM or negotiate authentication between the client and BIG-IP pool members may intermittently fail with repeated requests for re-authentication, or repeated notifications that their current credentials are incorrect.
NTLM or negotiate authentication between the client and BIG-IP pool members may intermittently fail.
- The OneConnect profile on the virtual server has a re-use mask other than 255.255.255.255. - You have no SNAT associated with the virtual server, or the affected virtual server is configured with both a SNAT and a SNAT persistence iRule. - The configuration contains elements that detach OneConnect connections.
To work around this issue, you can set the OneConnect re-use mask to 255.255.255.255. To do so, perform the following procedure: Impact of workaround: A OneConnect profile with a source mask of 255.255.255.255 will only aggregate connections originating from the same client IP address. This may result in less optimal connection re-use on the OneConnect profile associated with the virtual server. Log in to the BIG-IP Configuration utility. Click Local Traffic. Click Profiles. Click Other. Select OneConnect. Select the OneConnect profile associated with your virtual server. Change your Source Mask to 255.255.255.255. Click Update.
None
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.