For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

MarcelNL_153054's avatar
MarcelNL_153054
Icon for Nimbostratus rankNimbostratus
May 06, 2014

GTM placement for public DNS

Hi,

I got my hands on a GTM with version 9.4.5, which I want to use as a public DNS for jy domains. I have also bought a LTM which I will use as a reverse proxy for my webservers.

What i cannot find any info on is: where do jou place the GTM? I am a F5 novice. My intended setup:

Internet - firewall - gtm (dns) - ltm (rev.proxy) - firewall - servers
`


Is this correct? Does traffic actually flow through the gtm?? Or should this be:

`Internet - firewall - gtm (dns)
                   - ltm (rev. Proxy) - firewall - servers

What is the best way to go forward here? Any help is welcome!

Thanks, Marcel

20 Replies

  • I don't know what all of the options are pertaining to GTM and how granular it can get. For example, could be licensed for gtmd but not ZoneRunner (named). For our GTMs, we only have one line item in the active modules license section:

     

    Global Traffic Manager Module(Perpetual)

     

  • Ok, so this is the product info on my GTM... Looks like it only has the base licence. Reactivation went fine. Not sure why it does not have DNS listeners and Zonemanager.

    Maybe because it is a "LIMITED" so it only does IP load balancing? In that case I bought an overly-expensive switch 😞

    -------------------------------------------------------------------
     F5 Product Information for S99339
    -------------------------------------------------------------------
      F5 Product            : F5-BIG-LBL-1500 BIG-IP SWITCH: LOAD BALANCER LIMITED 1500
      Usage                 : Production
      Product Order Status  : Sales
      License Time Limit    : N/A
      Serial Number         : bip044471s (C36)
        Mac Address         : 00:01:d7:20:d0:40
        Appliance Status    : Replacement
    -------------------------------------------------------------------
     Service and Warranty Information
    -------------------------------------------------------------------
      Entitled Service      : 06-03-2006 - 12-31-2010 (F5-SVC-BIG-PRE-L1-3)
      Entitled Service      : 06-07-2006 - 12-31-2010 (F5-SVC-BIG-RMA-2)
      Entitled Service      : 06-07-2005 - 06-06-2006 (F5-SVC-BIG-STD-L1-3)
      Warranty End Date     : 06-06-2006
    -------------------------------------------------------------------
     Base Key for F5 Product BIG-IP v9.x for S99339
    -------------------------------------------------------------------
      Base RegKey           : QJOVBGC (Locked) BIG-IP
      F5 Platform           : C36
      First Activation Date : 06-07-2005
      Last Activation Date  : 05-07-2014
      License Time Limit    : N/A
      Mac Address           : 00:01:d7:20:d0:40
    -------------------------------------------------------------------
     License Modules for QJOVBGC (Locked) BIG-IP
    -------------------------------------------------------------------
      Serial Number         : TDLXAMC (Active, Product Module) LIC-PKG-BIG-LBLTD
    -------------------------------------------------------------------
    
  • Even weirder:

     

    The "named" service is running!

     

    (While the "radvd" service is down because it is "not licenced", so licencing is maybe not the issue here?)

     

  • Even weirder:

     

    The "named" service is running!

     

    (While the "radvd" service is down because it is "not licenced", so licencing is maybe not the issue here?)

     

  • Yeah, I don't see anything GTM related in this license file.

     

    You may have some local load balancing features with it based on that license though. What does the license look like your other BIG-IP appliance (the LTM)?

     

  • I believe you'll find named running on every BIG-IP appliance whether or not they are licensed for GTM. All of our LTMs and Enterprise Managers also have it.

     

  • Ok it seems gtmd is not present, nor is zrg. Maybe this GTM is not running as a GTM?

     

  • Ok it seems gtmd is not present, nor is zrg. Maybe this GTM is not running as a GTM?

     

  • Well, it's a BIG-IP appliance. What makes it a GTM is a license. You could turn it into an LTM or APM or whatever else based on a license.

     

    Yes, if it were licensed for GTM you'd definitely have gtmd and zrd.

     

  • Argh. You beat me to it :-) That is bad news.

     

    The LTM has a base licence with rev.proxy and 100 SSL