<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Technical Forum topics</title>
    <link>https://community.f5.com/t5/technical-forum/bd-p/TechnicalForum</link>
    <description>Technical Forum topics</description>
    <pubDate>Wed, 27 May 2026 20:05:34 GMT</pubDate>
    <dc:creator>TechnicalForum</dc:creator>
    <dc:date>2026-05-27T20:05:34Z</dc:date>
    <item>
      <title>F5 gtm last resort pool DNS Record problem</title>
      <link>https://community.f5.com/t5/technical-forum/f5-gtm-last-resort-pool-dns-record-problem/m-p/346589#M289187</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Big Ip v 17.1.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've found that when there is a GTM last Resort DNS Respone, and the DNS clients asks to a Microsoft DNS Server, Microsoft DNS server gives a NXDOMAIN response ( once every 3 ) .&lt;/P&gt;&lt;P&gt;If the DNS Client always asks directly to F5 DNS there is no problem.&lt;/P&gt;&lt;P&gt;I'm trying to figure out why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Graziano&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 09:47:30 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/f5-gtm-last-resort-pool-dns-record-problem/m-p/346589#M289187</guid>
      <dc:creator>GrazianoSommariva</dc:creator>
      <dc:date>2026-05-27T09:47:30Z</dc:date>
    </item>
    <item>
      <title>BIG-IQ CM Logs Not Receiving</title>
      <link>https://community.f5.com/t5/technical-forum/big-iq-cm-logs-not-receiving/m-p/346568#M289177</link>
      <description>&lt;P&gt;Once the disk space has been released, you need to rectify the condition below by running the provided command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# for idx in $(curl -ks -u admin:admin &lt;A href="https://localhost:9200/_cat/indices" target="_blank"&gt;https://localhost:9200/_cat/indices&lt;/A&gt; | awk '{print $3}'); do if [ $idx != ".opendistro_security" ]; then curl -k -u admin:admin -X PUT "&lt;A href="https://localhost:9200/$(echo%20$(echo%20$idx%20|%20cut%20-d/+%20-f1)*)/_settings?pretty" target="_blank"&gt;https://localhost:9200/$(echo $(echo $idx | cut -d\+ -f1)*)/_settings?pretty&lt;/A&gt;" -H 'Content-Type: application/json' -d'{"index.blocks.read_only_allow_delete": false}'; fi; done&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2026 06:43:27 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/big-iq-cm-logs-not-receiving/m-p/346568#M289177</guid>
      <dc:creator>Niranjan_biswas</dc:creator>
      <dc:date>2026-05-23T06:43:27Z</dc:date>
    </item>
    <item>
      <title>Dynamic import of data groups</title>
      <link>https://community.f5.com/t5/technical-forum/dynamic-import-of-data-groups/m-p/346555#M289168</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;We use data groups for various kind of black lists, such as undesirable user agents, for instance. That's really efficient, but requires a BigIP administrator intervention for any update. We'd like to switch authoritative origin for those lists to an external location, such as an internal git repository, in order to allow trusted people without access to the administration interface to update those lists in auditable manner, as we do for instance with our firewalls using "dynamic list" feature.&lt;/P&gt;&lt;P&gt;There seems to be no such native fonctionality in BigIPs, as even "external" dynamic lists actually relies on files hosted on local filesystem, not to arbitrary URLs. We could probably use a cron task to implement a pull-based update mechanism,&amp;nbsp; or use the API to periodically push changes, &amp;nbsp;but I'm not sure of the reliability of such ad-hoc mechanism, and the potential consequences in case of failure.&lt;/P&gt;&lt;P&gt;Is there any alternative for such kind of configuration delegation ?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Guillaume&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2026 11:24:40 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/dynamic-import-of-data-groups/m-p/346555#M289168</guid>
      <dc:creator>Guillaume_Rouss</dc:creator>
      <dc:date>2026-05-22T11:24:40Z</dc:date>
    </item>
    <item>
      <title>Trial License for F5 virtual edition in eve-ng</title>
      <link>https://community.f5.com/t5/technical-forum/trial-license-for-f5-virtual-edition-in-eve-ng/m-p/346554#M289167</link>
      <description>&lt;P&gt;Does anyone know the process around how to get trial license for F5 virtual edition in eve-ng? Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2026 09:36:02 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/trial-license-for-f5-virtual-edition-in-eve-ng/m-p/346554#M289167</guid>
      <dc:creator>AP84</dc:creator>
      <dc:date>2026-05-22T09:36:02Z</dc:date>
    </item>
    <item>
      <title>certitcate error</title>
      <link>https://community.f5.com/t5/technical-forum/certitcate-error/m-p/346548#M289166</link>
      <description>&lt;P&gt;we have issue when enable new certitcate this error it observed&lt;/P&gt;&lt;P&gt;ALPN, offering h2&lt;/P&gt;&lt;P&gt;* ALPN, offering http/1.1&lt;/P&gt;&lt;P&gt;* Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH&lt;/P&gt;&lt;P&gt;* successfully set certificate verify locations:&lt;/P&gt;&lt;P&gt;* CAfile: /etc/pki/tls/certs/ca-bundle.crt&lt;/P&gt;&lt;P&gt;CApath: none&lt;/P&gt;&lt;P&gt;* TLSv1.2 (OUT), TLS header, Certificate Status (22):&lt;/P&gt;&lt;P&gt;* TLSv1.2 (OUT), TLS handshake, Client hello (1):&lt;/P&gt;&lt;P&gt;* TLSv1.2 (IN), TLS handshake, Server hello (2):&lt;/P&gt;&lt;P&gt;* TLSv1.2 (IN), TLS handshake, Certificate (11):&lt;/P&gt;&lt;P&gt;* TLSv1.2 (OUT), TLS alert, Server hello (2):&lt;/P&gt;&lt;P&gt;* SSL certificate problem: unable to get local issuer certificate&lt;/P&gt;&lt;P&gt;* Closing connection 0&lt;/P&gt;&lt;P&gt;curl: (60) SSL certificate problem: unable to get local issuer certificate&lt;/P&gt;&lt;P&gt;More details here: https://curl.haxx.se/docs/sslcerts.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;curl performs SSL certificate verification by default, using a "bundle"&lt;/P&gt;&lt;P&gt;of Certificate Authority (CA) public keys (CA certs). If the default&lt;/P&gt;&lt;P&gt;bundle file isn't adequate, you can specify an alternate file&lt;/P&gt;&lt;P&gt;using the --cacert option.&lt;/P&gt;&lt;P&gt;If this HTTPS server uses a certificate signed by a CA represented in&lt;/P&gt;&lt;P&gt;the bundle, the certificate verification probably failed due to a&lt;/P&gt;&lt;P&gt;problem with the certificate (it might be expired, or the name might&lt;/P&gt;&lt;P&gt;not match the domain name in the URL).&lt;/P&gt;&lt;P&gt;If you'd like to turn off curl's verification of the certificate, use&lt;/P&gt;&lt;P&gt;the -k (or --insecure) option.&lt;/P&gt;&lt;P&gt;[M.Najm@BIGIP01:Active:In Sync&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 17:07:46 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/certitcate-error/m-p/346548#M289166</guid>
      <dc:creator>Najm</dc:creator>
      <dc:date>2026-05-21T17:07:46Z</dc:date>
    </item>
    <item>
      <title>about create wide ip,</title>
      <link>https://community.f5.com/t5/technical-forum/about-create-wide-ip/m-p/346533#M289152</link>
      <description>&lt;P&gt;i create generic host (Firewall) server and virtual server for wide ip,&lt;BR /&gt;i use health monitor is gateway_icmp but server and virtual server It keeps flapping between up and down, and the status is unstable.&lt;BR /&gt;i was cli device F5 ping test to device generic host ok, its ok, its dont have lost or packet loss&lt;BR /&gt;can you help me check issue&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 07:54:12 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/about-create-wide-ip/m-p/346533#M289152</guid>
      <dc:creator>nvhoanhai</dc:creator>
      <dc:date>2026-05-21T07:54:12Z</dc:date>
    </item>
    <item>
      <title>APM URL encoding Hardening?</title>
      <link>https://community.f5.com/t5/technical-forum/apm-url-encoding-hardening/m-p/346532#M289151</link>
      <description>&lt;P&gt;Some companies still use on-prem Sharepoint.. and Sharepoint is what it is.&lt;BR /&gt;We have had multiple servers deployed for quite some while now with ASM tuned for its quirks and so on.&lt;/P&gt;&lt;P&gt;However - after upgrading to version 17.5.1.6 from 17.5.1.5 we noticed some rather strange behaviors.&lt;/P&gt;&lt;P&gt;Like the edit modal button stopped working on certain sites, the upload button stopped working amongst some of the stuff. After some testing and stripping of functions we noticed that it started working when removing the APM policy. So the cogs started turning, what could be the issue with APM?&amp;nbsp;&lt;BR /&gt;Finally figured out that the links which did not work where not encoded, and the links which worked were.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So after some tweaking I got to building a simple http request rewrite iRule for simply encoding the stuff before sending to server.&lt;/P&gt;&lt;P&gt;But I do have some qualms about it - Are there any security risks according to you dear people that I might introduce by deploying this externally? Would you have solved it in any other way?&lt;/P&gt;&lt;P&gt;basically it's this:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;when HTTP_REQUEST {&lt;BR /&gt;# Re-encode characters that are illegal in URIs per RFC 3986 §2.2 / §3.4&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; set orig_uri [HTTP::uri]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; set new_uri [string map {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "\{" "%7B"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "\}" "%7D"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "|"&amp;nbsp; "%7C"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "\\" "%5C"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "^"&amp;nbsp; "%5E"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "`"&amp;nbsp; "%60"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; " "&amp;nbsp; "%20"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; } $orig_uri]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if { $new_uri ne $orig_uri } {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP::uri $new_uri&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;}&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 21 May 2026 07:44:48 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/apm-url-encoding-hardening/m-p/346532#M289151</guid>
      <dc:creator>Ted-Nordvall</dc:creator>
      <dc:date>2026-05-21T07:44:48Z</dc:date>
    </item>
    <item>
      <title>Layered ASM for APM login page protection</title>
      <link>https://community.f5.com/t5/technical-forum/layered-asm-for-apm-login-page-protection/m-p/346521#M289147</link>
      <description>&lt;P&gt;Has anyone successfully implemented&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://my.f5.com/manage/s/article/K000149701" target="_blank"&gt;https://my.f5.com/manage/s/article/K000149701&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Full VPN clinets stop working after this implementation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see below errors&lt;/P&gt;&lt;P&gt;Client machines interface IPs are not falling under a private subnet or exception subnet ranges provided by the APM server&lt;/P&gt;&lt;P&gt;The connected network is vulnerable of tunnel crack as LocalIP falls under the public IPs&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 00:30:45 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/layered-asm-for-apm-login-page-protection/m-p/346521#M289147</guid>
      <dc:creator>Zeeshan_Mohsin</dc:creator>
      <dc:date>2026-05-21T00:30:45Z</dc:date>
    </item>
    <item>
      <title>How to send statistics for a specific pool by email</title>
      <link>https://community.f5.com/t5/technical-forum/how-to-send-statistics-for-a-specific-pool-by-email/m-p/346519#M289145</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We need to send this specific view, as shown below, by email every two hours&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need have the status of a specific virtual server, the related pool, with the pool members' status and statistics every two hours&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I mean by statistics here is like what we see in BIG IP GUI, as below&lt;/P&gt;&lt;P&gt;Bits (In/Out)&lt;/P&gt;&lt;P&gt;Packets (In/Out)&lt;/P&gt;&lt;P&gt;Connections (Current/Maximum/Total)&lt;/P&gt;&lt;P&gt;Requests (Total)&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can it be done from BIG IQ if exist and how can it be done from BIG IP itself?&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 22:53:45 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/how-to-send-statistics-for-a-specific-pool-by-email/m-p/346519#M289145</guid>
      <dc:creator>User100000</dc:creator>
      <dc:date>2026-05-20T22:53:45Z</dc:date>
    </item>
    <item>
      <title>Sync error because Default logging profile and Custom profile both use local logging.</title>
      <link>https://community.f5.com/t5/technical-forum/sync-error-because-default-logging-profile-and-custom-profile/m-p/346518#M289144</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to setup a custom logging profile for bot manager because the default logging profile does not cover all the logging options that I need. I detached the default profile from the virtual server and attached my profile but it wont sync because of the error in the title. What are my options ? I can't setup remote logging at the moment.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 19:18:51 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/sync-error-because-default-logging-profile-and-custom-profile/m-p/346518#M289144</guid>
      <dc:creator>abaraip</dc:creator>
      <dc:date>2026-05-20T19:18:51Z</dc:date>
    </item>
    <item>
      <title>Need BIG-IP VE Lab License for Personal Study/Learning</title>
      <link>https://community.f5.com/t5/technical-forum/need-big-ip-ve-lab-license-for-personal-study-learning/m-p/346512#M289140</link>
      <description>&lt;P&gt;Hi F5 Community,&lt;/P&gt;&lt;P&gt;I am setting up a personal home lab to learn.&amp;nbsp;&lt;BR /&gt;F5 BIG-IP for certification preparation.&lt;/P&gt;&lt;P&gt;I have deployed BIG-IP VE but need a lab license.&amp;nbsp;&lt;BR /&gt;to access the management GUI.&lt;/P&gt;&lt;P&gt;Could anyone help me get a free lab/evaluation?&amp;nbsp;&lt;BR /&gt;license for personal learning purposes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 16:02:30 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/need-big-ip-ve-lab-license-for-personal-study-learning/m-p/346512#M289140</guid>
      <dc:creator>rohitkmr302</dc:creator>
      <dc:date>2026-05-20T16:02:30Z</dc:date>
    </item>
    <item>
      <title>BBRv3 Support</title>
      <link>https://community.f5.com/t5/technical-forum/bbrv3-support/m-p/346503#M289132</link>
      <description>&lt;P&gt;Hello, Community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://my.f5.com/manage/s/article/K50411377" target="_blank"&gt;https://my.f5.com/manage/s/article/K50411377&lt;/A&gt; BBR is supported on F5 boxes since TMOS 14.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/google/bbr" target="_blank"&gt;https://github.com/google/bbr&lt;/A&gt; BBR version 3 should be used currently&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does someone know which BBR version F5 devices use?&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 11:38:42 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/bbrv3-support/m-p/346503#M289132</guid>
      <dc:creator>Vladimir_Akhmarov</dc:creator>
      <dc:date>2026-05-20T11:38:42Z</dc:date>
    </item>
    <item>
      <title>Guest Role User Lost Visibility in ASM/WAF Module – LTM Working Fine</title>
      <link>https://community.f5.com/t5/technical-forum/guest-role-user-lost-visibility-in-asm-waf-module-ltm-working/m-p/346499#M289129</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm troubleshooting a strange issue on our F5 BIG-IP and hoping someone has run into this before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Module: ASM (WAF)&lt;/P&gt;&lt;P&gt;- User Role: Guest&lt;/P&gt;&lt;P&gt;- Partition Access: All Partitions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;A user with the Guest role and access to all partitions suddenly lost the ability to view any information in the ASM module. When navigating to Security &amp;gt; Application Security &amp;gt; Policies, the table shows "&lt;STRONG&gt;No records to display&lt;/STRONG&gt;" — even though policies exist and are active and viewable from other non-guest accounts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The strange part: LTM is working perfectly fine for this user. They can view virtual servers, pools, nodes, etc. without any issue. The problem is isolated to ASM only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers would be greatly appreciated. Happy to share outputs if needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 07:40:19 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/guest-role-user-lost-visibility-in-asm-waf-module-ltm-working/m-p/346499#M289129</guid>
      <dc:creator>A_hassanein</dc:creator>
      <dc:date>2026-05-20T07:40:19Z</dc:date>
    </item>
    <item>
      <title>Disk capacity on F5 rSeries</title>
      <link>https://community.f5.com/t5/technical-forum/disk-capacity-on-f5-rseries/m-p/346497#M289127</link>
      <description>&lt;P&gt;A customer of mine has F5 iSeries with LTM, DNS, APM, and ASM/AFM licenses. Disk capacity is 465 GB. He purchased F5 rSeries on which to set up a tenant, and the disk capacity reserved for tenants is only 294 GB.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe the new devices lack space, since the /config folder on the old ones is 75% full.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the output on rSeries:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;df -h /var/F5/system/cbip-disks&lt;/P&gt;&lt;P&gt;Filesystem Size Used Avail Use% Mounted on&lt;/P&gt;&lt;P&gt;/dev/mapper/partition_tenant-root &lt;STRONG&gt;294G&lt;/STRONG&gt; 36G 244G 13% /var/F5/system/cbip-disks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think about that?&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 13:25:24 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/disk-capacity-on-f5-rseries/m-p/346497#M289127</guid>
      <dc:creator>romolo82</dc:creator>
      <dc:date>2026-05-20T13:25:24Z</dc:date>
    </item>
    <item>
      <title>Logging F5 response via Logging profile</title>
      <link>https://community.f5.com/t5/technical-forum/logging-f5-response-via-logging-profile/m-p/346493#M289124</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am preparing a rule which limits requests per second based on IP and endpoint. There is also prepared response logging profile which sends logs to specific server with Elastic via TCP. Request limit in my rule is 3 per 1 second which triggers HTTP::respond with 429 status code but in my logs I can't see it. How possibly could I modify my iRule to log it too?&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 20:13:14 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/logging-f5-response-via-logging-profile/m-p/346493#M289124</guid>
      <dc:creator>kruszi123</dc:creator>
      <dc:date>2026-05-19T20:13:14Z</dc:date>
    </item>
    <item>
      <title>Migrate HW GTM 2600</title>
      <link>https://community.f5.com/t5/technical-forum/migrate-hw-gtm-2600/m-p/346475#M289113</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to migrate&amp;nbsp;2 cluster Active/Passive frrom serie i to serie r. They are LTM (active standby) and GTM-DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking about adding two new members to the cluster and temporarily expanding it to a 6-node cluster. Then, on the day of the intervention, we could bring them online and remove two of the i-series nodes. To do this i have to ask for new SELF-IPS, new cables.....etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone knows the best procedure to replacement these GTM/LTM nodes?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2026 08:30:39 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/migrate-hw-gtm-2600/m-p/346475#M289113</guid>
      <dc:creator>SuppEsp_AX</dc:creator>
      <dc:date>2026-05-18T08:30:39Z</dc:date>
    </item>
    <item>
      <title>Error in AWAF v17.1 DoS Dashboard</title>
      <link>https://community.f5.com/t5/technical-forum/error-in-awaf-v17-1-dos-dashboard/m-p/346470#M289110</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running v17.1.3.2 and provisioned for AWAF and LTM. After testing the DoS attack, the event had been detected. The issue is when I click on the Attack ID from the DoS Event Reporting, directing to DoS Dashboard, the Dashboard is showing the errors below and nothing is shown on the Attack Duration widget.&lt;/P&gt;&lt;P&gt;Tested this with previous version v17.1.1.3, it shows exactly the same errors.&lt;/P&gt;&lt;P&gt;Anyone had experienced this for AWAF with version 17.1? Are there any solutions for this.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2026 05:51:31 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/error-in-awaf-v17-1-dos-dashboard/m-p/346470#M289110</guid>
      <dc:creator>TravisLoke</dc:creator>
      <dc:date>2026-05-18T05:51:31Z</dc:date>
    </item>
    <item>
      <title>CLI Tool for BIG-IP - f5 cli</title>
      <link>https://community.f5.com/t5/technical-forum/cli-tool-for-big-ip-f5-cli/m-p/346463#M289103</link>
      <description>&lt;P&gt;I'm releasing a CLI tool for inspecting and manipulating configuration. It’s a whole suite of tools in one, from `f5 grep` through to the advanced jq-style `f5 query`&lt;/P&gt;&lt;P&gt;This tool is based on my last 20 years of using and abusing BIG-IP, and the ideas behind all the tooling I built along the way.&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/bitwisecook/tcl-lsp/blob/main/INSTALL-cli.md" target="_blank" rel="noopener"&gt;https://github.com/bitwisecook/tcl-lsp/blob/main/INSTALL-cli.md&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/bitwisecook/tcl-lsp/tree/main/docs/references/f5_query" target="_blank" rel="noopener"&gt;https://github.com/bitwisecook/tcl-lsp/tree/main/docs/references/f5_query&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/bitwisecook/tcl-lsp/tree/main/samples/for_f5_query" target="_blank" rel="noopener"&gt;https://github.com/bitwisecook/tcl-lsp/tree/main/samples/for_f5_query&lt;/A&gt;&lt;/P&gt;&lt;P&gt;there’s lots of documentation, worked examples, KCS style docs covering it, contending help including shell completion support.&lt;/P&gt;&lt;P&gt;It requires Python 3.10+ for now.&lt;/P&gt;&lt;P&gt;feel free to discuss here or raise issues on GitHub.&lt;/P&gt;&lt;P&gt;This is part of my much larger work on an LSP, MCP, and AI tooling for all editors and harnesses to improve f5 tooling.&lt;/P&gt;&lt;P&gt;The `query` verb can do stuff like&lt;/P&gt;&lt;LI-CODE lang=""&gt;$ f5 query --name ltm=ltm.conf --name gtm=gtm.conf --merge --raw '
    $gtm.gtm.wideip[] as $w
    | $w.pools[] as $gp
    | $gp.members[]
    | last(split(., ":")) as $vspath
    | $ltm.ltm.virtual[]
    | select(."full-path" == $vspath) as $vs
    | $vs.pool.members[]
    | tsv($w.name, $gp.name, $vs.name, $vs.pool, .address, port(.name))
  ' ltm.conf gtm.conf | sort -u&lt;/LI-CODE&gt;&lt;LI-CODE lang=""&gt;api.example.com    api_app_pool        api_vs   /Common/api_pool   10.0.2.20    8443
api.example.com    api_app_pool        api_vs   /Common/api_pool   10.0.2.21    8443
www.example.com    example_app_pool    web_vs   /Common/web_pool   10.0.1.10    80
www.example.com    example_app_pool    web_vs   /Common/web_pool   10.0.1.11    80&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2026 10:34:41 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/cli-tool-for-big-ip-f5-cli/m-p/346463#M289103</guid>
      <dc:creator>bitwisecook</dc:creator>
      <dc:date>2026-05-17T10:34:41Z</dc:date>
    </item>
    <item>
      <title>Question about source persistence across traffic group</title>
      <link>https://community.f5.com/t5/technical-forum/question-about-source-persistence-across-traffic-group/m-p/346461#M289101</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Hope you are doing great!&lt;BR /&gt;&lt;BR /&gt;I would like to know if it is supported to mirror persistence between 2 DC's across 2 Traffic Groups, each one is Active on a DC.&lt;BR /&gt;&lt;BR /&gt;DC 1 Active on TG1&lt;BR /&gt;DC 2 Active on TG2&lt;BR /&gt;&lt;BR /&gt;Client established connection on DC1, if it reconnected in DC2 traffic should be rerouted to DC1 backend. (There's no application level session synchronization)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Sat, 16 May 2026 07:45:24 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/question-about-source-persistence-across-traffic-group/m-p/346461#M289101</guid>
      <dc:creator>AmineZAKARIA</dc:creator>
      <dc:date>2026-05-16T07:45:24Z</dc:date>
    </item>
    <item>
      <title>Functionality questions regarding commands that we're using in a DNS_REQUEST related iRule</title>
      <link>https://community.f5.com/t5/technical-forum/functionality-questions-regarding-commands-that-we-re-using-in-a/m-p/346458#M289098</link>
      <description>&lt;P&gt;I opened a ticket w/F5 regarding this but they recommended I try DevCentral instead, so here we are :)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're currently in the process of creating and testing an iRule/configuration in a test environment with the intent of eventually applying it to the listeners in our F5 DNS/GTM production environment that will forward DNS requests made to our production F5 DNS/GTM environment with only specific criteria to a separate Windows DNS server to answer back through our production F5 DNS/GTM environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we have so far which appears to be working:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when DNS_REQUEST {&lt;/P&gt;&lt;P&gt;# Check if the query is for a TXT record and matches a specific FQDN&lt;/P&gt;&lt;P&gt;if { ([DNS::question type] equals "TXT") and ([string tolower [DNS::question name]] contains "_acme-challenge") } {&lt;/P&gt;&lt;P&gt;# Forward to a specific pool of DNS servers&lt;/P&gt;&lt;P&gt;DNS::disable dns-express&lt;/P&gt;&lt;P&gt;snat automap&lt;/P&gt;&lt;P&gt;translate address enable&lt;/P&gt;&lt;P&gt;pool /Common/dns_fwdtxttest_pool&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order for us to get it to work we had to add the following commands to the iRule that we found online:&lt;/P&gt;&lt;P&gt;DNS::disable dns-express&lt;/P&gt;&lt;P&gt;snat automap&lt;/P&gt;&lt;P&gt;translate address enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In both our test and production F5 DNS/GTM environments we:&lt;/P&gt;&lt;P&gt;-Do use dns-express&lt;/P&gt;&lt;P&gt;-Have source address translation set to none on our listeners&lt;/P&gt;&lt;P&gt;-Have address translation disabled on our listeners&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions are in regard to how those 3 commands may/may not affect other requests/traffic made to our production F5 DNS/GTM environment NOT being processed by the iRule when it gets triggered during and post completion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will the features/settings affected by those commands only apply to the request/traffic that triggers and is processed by the iRule, or all traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will the features/settings affected by those commands automatically revert back to how they are currently set/functioning prior to implementation in our production F5 DNS/GTM environment (DNS Express - enabled, source address translation - none, address translation - disabled) again once the iRule completes processing the triggered request/traffic, or do they need to be toggled back manually at the end of the iRule in some way again as well?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're just trying to make sure we have all our bases covered and are accounting for as much as we can before going live with it and potentially running into other unexpected issues with production requests/traffic upon implementation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All that being said - is there anything else that we may be missing/overlooking?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone out there have any thoughts/suggestions/guidance at all?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance and hope all is well!&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2026 22:09:53 GMT</pubDate>
      <guid>https://community.f5.com/t5/technical-forum/functionality-questions-regarding-commands-that-we-re-using-in-a/m-p/346458#M289098</guid>
      <dc:creator>OATI_Network_S1</dc:creator>
      <dc:date>2026-05-15T22:09:53Z</dc:date>
    </item>
  </channel>
</rss>

