Forum Discussion
port lockdown on GTM - do I have to include DNS ports?
I'd like to create custom port lockdown restrictions for a GTM to allow all hosts from my enterprise network and block management connection attempts from anywhere else. When I generate the lockdown list, do I need to explicitly whitelist DNS connections? Or will the GTM assume that since it's job is to be a DNS server, it should allow DNS by default without it needing to be explicitly allowed?
Thanks!
2 Replies
- Lee_Sutcliffe
Nacreous
You'll have to specify DNS. Only ICMP is permitted by default when creating a custom port lockdown and TCP/1028, 1029-1043 if you're running an HA pair. iQuery is also an exception if configured
https://support.f5.com/kb/en-us/solutions/public/13000/200/sol13250.html
- gsharri
Altostratus
Self-IP port lockdown settings do not affect a GTM listener object. Since a listener is really just a DNS virtual server the self-ip port lockdown could be set to "none" and GTM will still process DNS requests to the listener IP.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com