Forum Discussion
Are F5 devices capable of intercepting and rewriting DNS registration packets?
I have a device behind an F5 device.
It is registering in AD DNS on the otherside of the device the DNS registration packet has the source IP natted, but not the contents of the DNS packet. so.. AD DNS ends up with physical address rather than natted address. what are we doing wrong?
better question: am I right to assume the F5 should be natting the DNS packet contents?
2 Replies
- Abdul_Khadar_13
Nimbostratus
In summary – we have a number of application servers which are sat behind a F5 device which is performing NAT. On the other side of the F5 is an AD domain controller which is providing DNS for the application servers. Now… the application servers have physical addresses in the 172 range, but everyone access them through NAT using a 10 address. Unfortunately, the application servers keep updating their DNS records with their physical IP address (172) overwriting the NAT (10) address that everyone needs to use to access them. I can see from the DNS audit records on AD that the DNS update requests are coming from the 10 address, but contain the 172 address. This implies that the source of the DNS registration packet is being updated, but the contents are not. How should this work? Surely I don’t have to create (and continuously enforce) static IP addresses for all these servers… isn’t the F5 device capable of rewriting the DNS packet? - awilhelm
Employee
If this uses the dynamic update protocol specified by RFC 2136 (Windows Server documentation says that this is the case) it should be possible to create a virtual server to capture the DNS traffic specifically and an iRule to modify the DNS UPDATE requests in-flight.
The system does not have built-in functionality for this.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com