Updated Date: 07/07/2026
New Features in BIG-IP Version 17.1.1
See the following information about software lifecycle:
K8986: F5 software lifecycle policy
K5903: BIG-IP software support policy
BIG-IP version 17.1.1 introduces the following new features for LTM/TMOS:
Support for Client Certificate Constrained Delegation (C3D) is enabled with TLS 1.3.
From this release, BIG-IP supports handshakes with four additional cipher suites:
- ECDHE-ECDSA-AES128-CCM
- ECDHE-ECDSA-AES128-CCM8
- ECDHE-ECDSA-AES256-CCM
- ECDHE-ECDSA-AES256-CCM8
The Global Tunnel configuration parameters for VXLAN, NVGRE, and GENEVE tunnels that are applied to the BIG-IP are now driven from the F5OS-A or F5OS-C level.
Set the system DB flag “net.tunnel.globals.hostmanaged” value to False, in order to remove the restriction and enforce the BIG-IP driven tunnel configuration.
BIG-IP 17.1.1 introduces the following new enhancements in Distributed Cloud Services:
Transaction results are reported to improve bot defense. This release includes success and failure criteria for transaction results.
BIG-IP version 17.1.1 introduces the following new features for Advanced WAF:
For each and any type of masked data string, leading and/or trailing characters can be configured to be exposed, while masking rest of the string. For example, the first two and last three characters of a string, matching custom regular expression, can be exposed while the rest of the string characters are masked. These leading and trailing to be exposed characters are applicable for all custom patterns (they cannot be configured differently for each pattern).
To reduce false positive alarms on signatures and metacharacters, parameters can be configured as binary and, as a result, bypass inspection.