F5 F5CAB1 Question Answer
What will setting a Self IP to“Allow None”for Port Lockdown do?
Block HA communications, causing the systems to report their peer as offline and go active-active.
Block HA communications, causing the systems to report their peer as online ready.
Default allow port 1026 access between peer devices and traffic processing across the network failover.
ThePort Lockdownfeature controls which services a Self-IP will respond to.
Setting a Self-IP toAllow Nonemeans:
The Self-IP will not acceptanytraffic except the very limited, hard-coded HA ports such asTCP 4353used for device trust and configuration sync.
All other HA ports, including those needed for network failover and other HA mechanisms,are blocked.
When essential HA services cannot communicate, each device assumes its peer is down.
This results in:
HA failover misbehavior
Both devices thinking the other is offline
Potentialactive-active condition, which is not intended and can cause traffic disruption
Thus,Allow Nonecan break HA functionality unless the Self-IP is not used for HA links.
TESTED 09 Jan 2026
Copyright © 2014-2026 ACE4Sure. All Rights Reserved