Should we enable DNS DDOS protection on our on-premise F5 bigip ?

Hi, our used DNS cache /proxy service of Silverline, but now silverline was decommissioned, should we enable dns ddos protection on our on-premise F5 bigip? can someone pls advise, thanks?

What about using secondary zone in XC ? This way the attacks will never hit your on-prem F5 DNS/GTM?

The last article even shows what I mean.

Also for on-prem bigip you will need the AFM module for DNS DDOS protection.

Use F5 Distributed Cloud to control Primary and Secondary DNS