Loading...
Loading...
ICMP protocol 50 unreachable messages are not forwarded from the server-side to the client-side when a SNAT Virtual Server handles ESP flows that are not encapsulated in UDP port 4500 (RFC 3948). Other ICMP messages related to the server-side ESP flow may be similarly affected.
ICMP packets arriving on the server-side are not forwarded to the client-side.
-- BIG-IP system is forwarding ESP (protocol 50) packets. -- Virtual Server is configured with a SNAT pool or automap. -- The server-side IPsec peer sends ICMP protocol errors in response to the ESP packets.
Option 1: -- Enable NAT Detection (RFC 3947) on the IPsec peers. NOTE: NAT Detection (RFC 3947) is the correct way to implement IPsec peers when network address translation occurs between the two IPsec peers. Option 2: -- Remove NAT from the Virtual Server. -- Set the following sys db values: # tmsh modify sys db ipsec.lookupip value "enable" # tmsh modify sys db ipsec.lookupspi value "disable" NOTE: The sys db settings in option 2 do not resolve the ICMP issue if NAT is configured on the Virtual Server.
ICMP protocol 50 unreachable messages from the server-side are forwarded to the client-side.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.