Forum Discussion
DNSSEC Configuration issue
Hi Team,
I am trying to test DNSSEC on a trial version before rolling it out on production appliance. I have configured the Key signing key, Zone Signing key and mapped them to the DNSSEC Zone. However for some reason the DNSSEC zone is offline with error message: 'Offline (Enabled) - must contain at least one enabled KSK and enabled ZSK'
I have verified that the KSK and ZSK are both in enabled state. Any pointers on why this could be happening?
Best Regards,
Shridhar Acharya
3 Replies
- Gordon_Bailey-MHistoric F5 AccountThanks - will give it a try! 
- Shridhar21389_3Nimbostratus Below changes solved my problem: 
 - Ensure that at least one data center and a server object representing the BIG-IP device exist in the BIG-IP system configuration.
 - The BIG IP device server object should be added with the self IP and not management IP
- Gordon_Bailey-MHistoric F5 AccountDid you find the answer on this? Playing in my lab and I get the same thing! 
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com