Jan 30, 2024

F5 XC secondary dns to BIGIP GTM/DNS


i following the below article to transfer zone from on prem BIGIP Authoritative DNS to F5 XC as slave.

as per article i have added ACL to allow only XC IP's

acl "F5-Cloud" {;;

also added key in zone

allow-transfer { key <key_name>; localhost; };


according this configuration any ip with tsig key is allowed to zone transfer.

how to restrict only to XC ip with tsig key

