For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Rabbit23_116296's avatar
Rabbit23_116296
Icon for Nimbostratus rankNimbostratus
Apr 07, 2014

GTM DNS trickery

So very new to the zonerunner implementation but it looks 'bind-ish'. So what we are trying to accomplish is use GTM both internal and external for delegated zones, but I don't want it to serve DNS requests externally. I'd rather just use dump our regular public NS entries in the external view and slave it to them so that they are in fact the authoritative servers.

 

Is what I'm trying to do possible?

 

2 Replies

  • Yes zonerunner is a GTM interface into BIND.

     

    I can see why you might want to slave from regular DNS to GTM, but not the other way - the reason being that changes to 'regular' DNS servers are less stringently controlled than changes to GTM in my company, so slaving to a non-GTM server is more easily maintained than updating the GTM directly, however I see no reason it wouldn't work.

     

  • Thanks - it's really just the way our company works. We won't be able to make GTM authoritative because of how we manage BIND with PowerDNS.

     

    It also is means that we will have multiple points of entry into the environment. So for us it makes sense to offload the actual DNS NS serving to BIND. Problem is however I cannot seem to add the F5 NS entry from the master zone on GTM nor add a NS that is outside of the delegated zone.