Forum Discussion
Chris_18457
Cirrus
Jun 10, 2016LTM DNS root reachout on mgmt, disable?
Our security group noted that our LTMs (2000s; v12.0HF1) are sending DNS queries out their mgmt interface that are being blocked by our access controls for that network. It should be noted the envir...
AaronJB
Jun 13, 2016Ret. Employee
This sounds like you are running into bug ID567293, the recursive query to the root hints is a dead giveaway; if your firewalling responds with a Port Unreachable it triggers a tight loop that will eventually lead to resource exhaustion - see https://support.f5.com/kb/en-us/solutions/public/k/61/sol61521270.html
Fixed in 12.0 HF3 and onward.
- Chris_18457Jun 13, 2016
Cirrus
Thanks for the link to the bug. I have reviewed what they observed in the bug, and I dont see the "...out of memory..." logs in /var/log/kern.log. However, I will note that we upgraded our lab 2000s and 10250V clusters to 12.1 (as part of our reoccuring upgrade cycle) and noticed that we no longer see the reachouts on the mgmt interface. So the end results looks to be the same...upgrade (maybe patch with hot fix). Thanks!
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects