For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

John_Heyer_1508's avatar
John_Heyer_1508
Icon for Cirrostratus rankCirrostratus
Mar 18, 2016

GTM sending DNS replies from sourceh IP of 127.0.0.1

Funny behavior on a BigIP-VE 11.6.0 VM running the GTM module. I needed to create a zone for testing, contained within its own view so it only was hit for certain clients, and did this under ZoneRunner. Everything works fine, except I now see periodic messages like this from the firewall it's behind:

Mar 18 14:34:16 FIREWALL : %ASA-2-106016: Deny IP spoof from (127.0.0.1) to 12.34.56.78 on interface INSIDE

I know that F5 does not officially support the BIND backend aka NAMED aka ZoneRunner so approaching them for an explanation is probably not going to go anywhere. Just curious if anyone had seen this.

The view in ZoneRunner uses 127.10.0.0 for loopback, so I'm really confused how 127.0.0.1 is getting introduced, even if it's a bug

No RepliesBe the first to reply