Forum Discussion

rmd1023's avatar
rmd1023
Icon for Nimbostratus rankNimbostratus
Jun 02, 2015

port lockdown on GTM - do I have to include DNS ports?

I'd like to create custom port lockdown restrictions for a GTM to allow all hosts from my enterprise network and block management connection attempts from anywhere else. When I generate the lockdown list, do I need to explicitly whitelist DNS connections? Or will the GTM assume that since it's job is to be a DNS server, it should allow DNS by default without it needing to be explicitly allowed?

 

Thanks!

 

2 Replies

  • Self-IP port lockdown settings do not affect a GTM listener object. Since a listener is really just a DNS virtual server the self-ip port lockdown could be set to "none" and GTM will still process DNS requests to the listener IP.