For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

ragunath154's avatar
ragunath154
Icon for Cirrostratus rankCirrostratus
Jan 30, 2024

F5 XC secondary dns to BIGIP GTM/DNS

hi 

i following the below article to transfer zone from on prem BIGIP Authoritative DNS to F5 XC as slave.

https://f5cloud.zendesk.com/hc/en-us/articles/7980850576535-How-to-set-up-F5-Distributed-Cloud-DNS-as-Secondary-for-BIG-IP-DNS-GTM

as per article i have added ACL to allow only XC IP's

acl "F5-Cloud" {
  52.14.213.208/32;
  3.140.118.214/32;
};

also added key in zone

allow-transfer { key <key_name>; localhost; };

 

according this configuration any ip with tsig key is allowed to zone transfer.

how to restrict only to XC ip with tsig key

No RepliesBe the first to reply