Forum Discussion
port lockdown on GTM - do I have to include DNS ports?
I'd like to create custom port lockdown restrictions for a GTM to allow all hosts from my enterprise network and block management connection attempts from anywhere else. When I generate the lockdown list, do I need to explicitly whitelist DNS connections? Or will the GTM assume that since it's job is to be a DNS server, it should allow DNS by default without it needing to be explicitly allowed?
Thanks!
2 Replies
- gsharri
Altostratus
Self-IP port lockdown settings do not affect a GTM listener object. Since a listener is really just a DNS virtual server the self-ip port lockdown could be set to "none" and GTM will still process DNS requests to the listener IP.
- Lee_Sutcliffe
Nacreous
You'll have to specify DNS. Only ICMP is permitted by default when creating a custom port lockdown and TCP/1028, 1029-1043 if you're running an HA pair. iQuery is also an exception if configured
https://support.f5.com/kb/en-us/solutions/public/13000/200/sol13250.html
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com