Forum Discussion
GTM placement for public DNS
Hi,
I got my hands on a GTM with version 9.4.5, which I want to use as a public DNS for jy domains. I have also bought a LTM which I will use as a reverse proxy for my webservers.
What i cannot find any info on is: where do jou place the GTM? I am a F5 novice. My intended setup:
Internet - firewall - gtm (dns) - ltm (rev.proxy) - firewall - servers
`
Is this correct? Does traffic actually flow through the gtm?? Or should this be:
`Internet - firewall - gtm (dns)
- ltm (rev. Proxy) - firewall - servers
What is the best way to go forward here? Any help is welcome!
Thanks, Marcel
20 Replies
- Cory_50405
Noctilucent
The GTM can really be placed anywhere, as long as it can be reached by external users for DNS queries. It is only going to handle the DNS traffic. Any subsequent data connection (HTTP, FTP, etc.) is going to go directly to the LTM. So essentially there are two separate communication flows:
DNS (UDP or TCP port 53):
External client queries for one of your domains (www.company.com for example). The query will traverse through the normal DNS root servers and ultimately arrive at your GTM. Your GTM will provide a response based on a configured wide IP, ZoneRunner record, etc. This response will be for a virtual server IP address hosted on your LTM.
Data (TCP port 80 in this case):
After the client has resolved the FQDN, it'll then attempt its data connection. Let's say it's a web connection. The client will begin an HTTP connection to the LTM virtual server IP address that it was given when it performed the DNS lookup.
- MarcelNL_153054
Nimbostratus
Thank you very much for this excellent answer. This maken the setup completely clear to me!
One related question: where can I find Zonerunner? I am running BIG-IP 9.4.8 but cant find it anywhere....
Thanks!! Marcel
- Cory_50405
Noctilucent
You can find ZoneRunner information for 9.4.8 here:
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm_config_943/gtm_zfd.html1004455
- MarcelNL_153054
Nimbostratus
Hi,
That article explains how to use zonerunner.
I just cannot find it anywhere. I don't have a menu option "zonerunner", also no "listeners" option in the menus.
Do I need to configure something to enable it?
- Cory_50405
Noctilucent
That's odd, both ZoneRunner and the Listeners should be under Global Traffic. Is your GTM properly licensed?
- MarcelNL_153054
Nimbostratus
I bought the device second hand. It says the base licence is active. Upgrading to 9.4.8 worked ok too.
Don't have a maintenance contract, but I could try to reactivate the licence?
- MarcelNL_153054
Nimbostratus
I bought the device second hand. It says the base licence is active. Upgrading to 9.4.8 worked ok too.
Don't have a maintenance contract, but I could try to reactivate the licence?
- Cory_50405
Noctilucent
There should definitely be listeners there. Otherwise the device won't be setup to listen for and respond to DNS queries. Unsure if reactivating the license will have any impact.
Under System -> License, what does it specify under the active modules section?
- MarcelNL_153054
Nimbostratus
I think it only listed the base module. Do you need other modules for listeners / dns? That would be weird since that is the gtm's only job :-)
I will check again in 2 hours when I am back in the office.
- MarcelNL_153054
Nimbostratus
Another thing I noticed is that the LCD backlight menu is missing from the lcd. It only allows the contrast to be set. Even after the upgrade....
Strange stuff
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com