Forum Discussion
F5 AFM (13.1.1) Using FQDN in rules - troubleshooting
- Feb 28, 2019
Thanks for the information, I actullay got a fix from F5 support. As follows;
1- Navigate to 'Network ›› DNS Resolvers : DNS Resolver List' and click on your DNS resolver 'dns-resolver'
2- Under Forward zones, click 'Add' and for the 'Name' Enter the dot sign (.), for the address add one of your above DNS servers addresses.
Have you tried checking the AFM DNS cache to see if the FQDN being resolved matches what you are expecting?
tmsh show security firewall fqdn-info fqdn
Does the FQDN in question resolve to a single IP or multiple IPs?
You can also try enabling FQDN debugging temporarily:
tmsh modify sys db log.fw_fqdn.level value debug
To turn off FQDN debugging:
tmsh modify sys db log.fw_fqdn.level reset-to-default
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com