CNF Fixes and Known Issues¶
This list highlights fixes and known issues for this CNF release.
Known Issues¶
2008705-2¶
‘drop counter’ is incremented for flow filter with session reporting when cpu loaded to 8%
Component: PE
Symptoms:
The drop counters in the pem_actions_stat table continue to increase, and new subscriber logins fail.
Conditions:
The Policy Enforcer is provisioned, and the PEM policy is configured for session reporting. A high number of subscribers are attempting to log in.
Impact:
New subscriber logins will not be successful, leading to traffic impact.
Workaround:
Disable the session reporting action in the PEM policy.
1780329-2¶
CR status for SecureContext and ALG remains in False state when AFM pod is restarted during config application
Component: Ingress
Symptoms:
Status remains False after a successful configuration. The root cause for this issue is that there is no CR status updates when CRs send to PCCD as part pccdGrpcConfig, so when a CR fails to send the first time (because of the AFM pod restart), the status for each of the CRs that get sent to PCCD will go into False ready status despite being configured correctly.
Conditions:
CR status for SecureContext and ALG CRs remains in False state when AFM pod is restarted during config application.
Impact:
CR status remains in False state. However, the configuration change still happens so it should work as expected.
Workaround:
CR Status is updated when there is a CR add/update/delete event or a dependent CR has an add/update/delete event.
1574561-4¶
The tmm-init ConfigMap Overwritten during Rolling Upgrade
Symptoms:
During an f5ingress upgrade, custom TMM user data stored in the ConfigMap is overwritten, resulting in the loss of custom configurations.
Conditions:
Upgrade f5ingress Helm chart to a newer version.
Impact:
Overwriting custom configuration can lead to interruptions in services provided by CNF/SPK.
Workaround:
Save the tmm-init configuration before the upgrade. After updating the f5ingress Helm chart, transfer the custom configuration from the saved tmm-init file to the user_conf.tcl section of the new tmm-init configuration.
1968153-3¶
Traffic stats missing drop counter for trunk usecases
Component: FSM
Symptoms:
Traffic stats are not present when packet are dropped when using a trunk interface.
Conditions:
The trunk does not have any interfaces to forward traffic.
Impact:
Missing diagnostics.
2138129-1¶
Fluent-bit ARM64 image hits unsupported page size issues on ARM64 AKS cluster
Component: Toda_fluentbit
Symptoms:
When configuring a Linux kernel with the page size for 64K page size: CONFIG_ARM64_64K_PAGES=y, Fluentbit fails to start with an error “Unsupported system page size”.
Conditions:
When configuring a Linux kernel with the page size for 64K page size: CONFIG_ARM64_64K_PAGES=y.
Impact:
Fluentbit fails to start with an error “Unsupported system page size”.
1578457-3¶
Inconsistent imagePullSecret Parameter in CNF Helm Charts
Component: DSSM
Symptoms:
Inconsistencies in the imagePullSecret parameter in the CNF Helm chart can cause confusion and potentially lead to failed deployments of some pods.
Conditions:
When deploying pods using the latest CNF tarball in OCP.
Impact:
Unable to deploy CNF properly or troubleshoot pod deployment failures efficiently due to incorrect imagePullSecret configuration.
2152049-2¶
NAT IPs may be duplicated after deleting a TMM pod and recreating the NAT Custom Resource
Component: CGNAT
Symptoms:
ultiple TMM pods may reserve and utilize the same NAT IPs, or some NAT IPs may appear as both reserved and available simultaneously. This behavior can be observed in TMM statistics, particularly in the fw_nat_reserv_ip_range_stat table and MRFDB output.
Conditions:
This issue arises when a TMM pod is deleted, and the NAT Custom Resource (CR) is deleted and recreated within the NAT IP reservation timeout period (default: 15 minutes) following the pod’s deletion.
Impact:
This can cause client connection failures because the server-side router may send return traffic to incorrect TMM pods.
Workaround:
Delete the NAT Custom Resource (CR) and recreate it. Ensure that no TMM pods were deleted within the NAT IP reservation timeout period (default: 15 minutes) prior to recreating the CR.
1823977-2¶
Logs for TMM container is unavailable through console output when fluentbit container is enabled in TMM pod
Component: FSM
Symptoms:
When the fluentbit container is enabled for the f5-tmm pod, the f5-tmm container logs will not be outputted to the console. However, the f5-tmm container logs can still be found in the f5-toda-fluentd pod (located under “/var/log/f5”)
Conditions:
Fluentbit container is enabled and running in the f5-tmm pod.
Impact:
F5-tmm container logs will not be outputted through console and can only be found in the f5-toda-fluentd pod.
Workaround:
The f5-tmm container logs can still be found in the f5-toda-fluentd pod (located under “/var/log/f5”).
2196905-1¶
Intermittent traffic fails after VLAN CR edit with PoD DAG enabled
Component: DAG
Symptoms:
Traffic is not delivered to the designated receiving VLAN when Pod DAG is enabled.
Conditions:
Number of IPs configured in VLAN CRD is more than number of TMM pods and the traffic receiving VLAN’s pod_hash is configured with either SRC_ADDR or DST_ADDR.
Impact:
Intermittent traffic failure.
Workaround:
Scale up or down by 1 pod. If required, you can restore the deployment to its original size.”
2202337-1¶
F5BigIpsPolicy CR status could remain False even though f5-ipsd pod is configured
Component: IPS
Symptoms:
The controller lacks a reconciliation mechanism to retry status updates for previously failed CRs when IPSD pod recovers. The status update logic only executes during initial CR creation/update or explicit CR modification events. When configuration delivery fails due to pod unavailability, the status is set to “Failed”, but no automatic reconciliation is triggered to reassess and update the status once the IPS pod becomes operational again and configs are delivered to it successfully.
Conditions:
When configuration delivery to the IPS pod fails, F5BigIpsPolicy CR statuses are marked as “Failed”. However, after the IPS pod becomes healthy, subsequent successful configuration deliveries do not trigger a status update on the affected CRs. The CRs remain in the “Failed” state despite the configurations being successfully applied to the IPS pod.
Impact:
Users cannot determine the actual state of their configurations and use-case may appear misconfigured when they are actually functioning correctly. This is true for AFM, DWBLD, BDOSD and Downloader pods as well.
Workaround:
Users need to manually trigger CR reconciliation by performing a trivial update/re-create to the affected CRs to force the controller to re-evaluate and update the status. Or Users can restart the CNE controller pod.
2200517-1¶
Hardware acceleration for IPv6 is not supported.
Component: FSM
Symptoms:
MOn the CX7 NIC, BIG-IP Next for Kubernetes hardware acceleration is not supported for IPv6 traffic. Only IPv4 traffic offloading is available, including IPv4 flow offloading, IPv4 NAT44 offloading, and ACL offloading.
Conditions:
BIG-IP Next for Kubernetes running on the CX7 NIC.
Impact:
IPv6 traffic is not optimized for acceleration.
1959509-2/ 2181853-1¶
Session creation failure when a new unknown subscriber lands on PEM
Component: PEM
Symptoms:
Session creation fails when a burst of new subscribers occurs. Issue arises when scaling to 2000 subscribers with heavy simultaneous session creation.
Conditions:
Occurs with a large burst of simultaneous new subscriber flows while adding new unknown subscribers to PEM. Adding subscribers at a rapid rate exceeds session creation rate capabilities.
`
Impact:
Session creation fails, leading to performance degradation and error in session states. Throughput tests might be impacted if subscriber addition is not handled correctly.
Workaround:
Add subscribers at a slow rate, not exceeding 30 connections with unique IPs per second. Ensure subscriber addition happens first at a slow pace. Once subscribers are added, start the traffic and proceed with performance measurements.