For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

tuannguyen1712's avatar
tuannguyen1712
Icon for Altocumulus rankAltocumulus
Jul 10, 2019

BigIP DNS in route domain

Hi guys, really need your help!!!

I have 4 F5 (2 running DNS, 2 running LTM, both in HA pair). since this system needs to service for public user (internet) and private user (over wan) I need to configure bigIP DNS and bigIP LTM in 2 route domain. BigIP LTM run 2 route domain is ok for me, but I find some troubles to configure BigIp DNS with 2 route domain. The steps to configure vlan, self IP, static route with route domain is ok (same as LTM) but when I configure servers on big IP DNS, I can not assign route domain ID to server, this leads to one thing: the server is down forever.

5 Replies

  • Hello.

    Base on the documentation:

    ​"Important: On a BIG-IP® system that includes both Local Traffic Manager™ (LTM®) and Global Traffic Manager™ (now BIG-IP ®DNS), all IP addresses that BIG-IP DNS references (virtual IP addresses, link addresses, and so on) must be associated with route domain 0."

    REF - https://techdocs.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-routing-administration-12-0-0/9.html

    You can use route domains in different LTM devices using this

    REF - https://techdocs.f5.com/kb/en-us/products/big-ip-dns/manuals/product/bigip-dns-implementations-13-0-0/11.html

    KR,

    Dario.

    • tuannguyen1712's avatar
      tuannguyen1712
      Icon for Altocumulus rankAltocumulus

      you are correct bro, it is unable to configure big-ip dns with route domain. Thank you so much!

    • tuannguyen1712's avatar
      tuannguyen1712
      Icon for Altocumulus rankAltocumulus

      By the way, do you know the big-ip dns feature which allows to resolve the same domain to different virtual server for public and private request?

      • Dario_Garrido's avatar
        Dario_Garrido
        Icon for Noctilucent rankNoctilucent

        I don't know if I understand correctly, but you can apply an iRule to one VS to respond differently base on the source ip for example.