Forum Discussion
DNS Request to VS?
Hello,
we found on our Firewall lots of DNS-Requests from the floating IP to some VS (with ASM-Policy).
Now we want the Firewall to only allow DNS-Requests to the known DNS-Servers.
Question: is this normal behaviour? The BIGIP has DNS-Resolver configured.
Where can I check the Config-Utility?
Thanks for any hint.
Karl
1 Reply
- Jmtaylor
Moderator
Hello here is some information that I was able find (Formatting generated by AI)
https://my.f5.com/manage/s/article/K15430
https://my.f5.com/manage/s/article/K21272
https://my.f5.com/manage/s/article/K13221
You can check and modify the DNS Resolver settings in the BIG-IP UI (Configuration Utility) by following these steps:
- Log in to the Config-Utility (GUI):
- Open a browser and navigate to your BIG-IP management IP or hostname (e.g., https://<management-ip>).
- Log in with your management credentials.
- Navigate to the DNS Resolver Settings:
- Go to System > Configuration > Device > DNS.
- Check the settings under DNS Resolver or System DNS configuration.
- Verify the listed DNS servers are the expected ones.
- Check Virtual Server (VS) and ASM Policies:
- Navigate to Local Traffic > Virtual Servers to review the virtual server bound to the floating IP.
- Locate the associated DNS Resolver profile, if any, and associated policies.
- For ASM: Under Security > Application Security > Policy Building or Policies, ensure policies are configured correctly and not triggering unintended DNS lookups.
You can check and modify the DNS Resolver settings in the BIG-IP UI (Configuration Utility) by following these steps:
- Log in to the Config-Utility (GUI):
- Open a browser and navigate to your BIG-IP management IP or hostname (e.g., https://<management-ip>).
- Log in with your management credentials.
- Navigate to the DNS Resolver Settings:
- Go to System > Configuration > Device > DNS.
- Check the settings under DNS Resolver or System DNS configuration.
- Verify the listed DNS servers are the expected ones.
- Check Virtual Server (VS) and ASM Policies:
- Navigate to Local Traffic > Virtual Servers to review the virtual server bound to the floating IP.
- Locate the associated DNS Resolver profile, if any, and associated policies.
- For ASM: Under Security > Application Security > Policy Building or Policies, ensure policies are configured correctly and not triggering unintended DNS lookups
- Log in to the Config-Utility (GUI):
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com