Forum Discussion
Why we need to allow DNS on Self IP?
My GTM set up has a self IP as a listener, so I was going to apply the irule to drop tkey requests, however F5 have come back with the following:-
Disabling of port 53 on the self-IP: F5 has advised that although the ip address of self-ip and listener are the same, they both operate at different levels of the F5 OS. The self-ip operates at the linux level while the listener operates at the TMOS software level. Therefore with the recommendations, the config of the selfip will not create a listener on port 53 (directed to daemon bind), but the config of the listener will be created on port 53 and incoming traffic will be processed by F5 software.
Does this sound correct, think I would still be happier applying the irule?
Thanks,
Martin
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com