Forum Discussion

Davethoonsen's avatar
Davethoonsen
Icon for Altocumulus rankAltocumulus
Sep 19, 2019
Solved

DNS server in route domain

Hi,

 

We are currently running an F5 instance without referenced DNS server, but would like to make use of this so we can reference NTP pools as well.

The challenge i'm facing is that our DNS servers all reside on networks that are used in route domains and not in the partition default route domain. Is it possible to reference a DNS server under System » Configuration » Device » DNS that actually resides in a route domain?

 

I've read upon the possibility to provision the Global Traffic module (DNS) to make this possible, but I'm yet uncertain what would be the best option in this case. My goal so far is to only resolve NTP pool(s), but would like to use internal DNS server firsthand before reaching out to public DNS servers.

 

Thanks in advance.

 

Kind regards,

 

Dave

  • Hi,

     

    Why you don't use route domain 0 for DNS, AD, NTP, ... (system part)?

     

    for information:

    The BIG-IP APM DNS configuration does not currently support route domains. All DNS communication must happen in default route domain 0. As a result, the system does not support multi-tenant configurations where name resolution on the BIG-IP APM must be separated per route-domain tenant.

    To provide access to BIG-IP APM resources in a multi-tenant environment, you must configure, in the BIG-IP APM system, a shared DNS server that is reachable by all tenants.

     

    https://support.f5.com/csp/article/K20465715

     

    Regards

     

     

2 Replies

  • Hi,

     

    Why you don't use route domain 0 for DNS, AD, NTP, ... (system part)?

     

    for information:

    The BIG-IP APM DNS configuration does not currently support route domains. All DNS communication must happen in default route domain 0. As a result, the system does not support multi-tenant configurations where name resolution on the BIG-IP APM must be separated per route-domain tenant.

    To provide access to BIG-IP APM resources in a multi-tenant environment, you must configure, in the BIG-IP APM system, a shared DNS server that is reachable by all tenants.

     

    https://support.f5.com/csp/article/K20465715

     

    Regards

     

     

  • Hi Youssef,

     

    Thank you for your response. I haven't considered using route domain 0 for the system part. In the meanwhile I've transferred the route domain to the default partition and am able to use the services I need. Thanks for thinking along!

     

    Kind Regards,

     

    Dave