Forum Discussion

liccccboeh_3569's avatar
liccccboeh_3569
Icon for Nimbostratus rankNimbostratus
Sep 16, 2018

BIG-IP DNS allowing zone transfer to slave linux server

Hello!

 

I'm trying to get F5 to allow zone transfer to another Linux Bind server, which will be a slave for backup purposes.

 

BIG-IP is authoritive and is answering to all DNS requests for that zone file correctly.

 

I've configured another Linux Named(Bind) server and set it up as slave. When I'm doing "dig axfr "@F5-VIRTUAL-DNS-IP example.com" and check F5 LTM logs, I get "REFUSED qr, aa" for that query.

 

  • in F5 zone file for "example.com" I added allow-transfer/allow-notify IP for my Linux Slave server.
  • I got 2 listeners in F5 for UDP / TCP.
  • under DNS -> Delivery -> Profiles -> "DNS Traffic" I allowed "ZONE-TRANSFER"

And now I've ran out of ideas.

 

All help is appreciated.

 

    1. DNS -> Delivery -> Nameservers and create a entry for all your slave linux bind servers
    2. DNS -> ZONES -> Zones -> Zone list choose correct zone ("example.com") and in "Zone Transfer Clients" add previously created slave servers to active. Previously there should be only 127.0.0.1.
    1. DNS -> Delivery -> Nameservers and create a entry for all your slave linux bind servers
    2. DNS -> ZONES -> Zones -> Zone list choose correct zone ("example.com") and in "Zone Transfer Clients" add previously created slave servers to active. Previously there should be only 127.0.0.1.