Using Distributed Cloud DNS Load Balancer with Geo-Proximity and failover scenarios

Introduction

To have both high performance and responsive apps available on the Internet, you need a cloud DNS that’s both scalable and one that operates at a global level to effectively connect users to the nearest point of presence. The F5 Distributed Cloud DNS Load Balancer positions the best features used with GSLB DNS to enable the delivery of hybrid and multi-cloud applications with compute positioned right at the edge, closest to users.

With Global Server Load Balancing (GSLB) features available in a cloud-based SaaS format, the Distributed Cloud DNS Load Balancer has a number distinct advantages:

  • Speed and simplicity: Integrate with DevOps pipelines, with an automation focus and a rich and intuitive user interface
  • Flexibility and scale: Global auto-scale keeps up with demand as the number of apps increases and traffic patterns change
  • Security: Built-in DDoS protection, automatic failover, and DNSSEC features help ensure your apps are effectively protected.
  • Disaster recovery: With automatic detection of site failures, apps dynamically fail over to individual recovery-designated locations without intervention.

Adding user-location proximity policies to DNS load balancing rules allows the steering of users to specific instances of an app. This not only improves the overall experience but it guarantees and safeguards data, effectively silo’ing user data keeping it region-specific. In the case of disaster recovery, catch-all rules can be created to send users to alternate destinations where restrictions to data don’t apply.

Integrated Solution

This solution uses a cloud-based Distributed Cloud DNS to load balance traffic to VIP’s that connect to region-specific pools of servers. When data privacy isn’t a requirement, catch-all rules can further distribute traffic should a preferred pool of origin servers become unhealthy or unreachable.

The following solution covers the following three DNS LB scenarios:

  • Geo-IP Proximity
  • Active/Standby failover within a region
  • Disaster Recovery for manually activated failovers

The configuration for this solution assumes the following:

  1. The app is in multiple regions
  2. Users are from different regions
  3. Distributed Cloud hosts/manages/is delegated the DNS domain or subdomain
  4. (optional) Failover to another region is allowed

Prerequisite Steps

Distributed Cloud must be providing primary DNS for the domain. Your domain must be registered with a public domain name registrar with the nameservers ns1.f5clouddns.com and ns2.f5clouddns.com. F5 XC automatically validates the domain registration when configured to be the primary nameserver.

Navigate to DNS Management > domain > Manage Configuration > Edit Configuration >> DNS Zone Configuration: Primary DNZ Configuration > Edit Configuration. Select “Add Item”, with Record Set type “DNS Load Balancer

Enter the Record Name and then select Add Item to create a new load balancer record.

This opens the submenu to create DNS Load Balancer rules.

DNS LB for Geo-Proximity

Name the rule “app-dns-rule” then go to Load Balancing Rules > Configure.

 Select “Add Item” then under the Load Balancing Rule, within the default Geo Location Selection, expand the “Selector Expression” and select “geoip.ves.io/continent”.

Select Operator “In” and then the value “EU”. Click Apply. Under the Action “Use DNS Load Balancer pool”, click “Add Item”.

Name the pool “eu-pool”, and under Pool Type (A) > Pool Members, click “Add Item”.

Enter a “Public IP”, then click “Apply”. Repeat this process to have a second IP Endpoint in the pool.

Scroll down to Load Balancing Method and select “Static-Persist”.

Now click Continue, and then Apply to the Load Balancing Rule, and then “Add Item” to add a second rule.

In the new rule, choose Geo Location Selection value “Geo Location Set selector”, and use the default “system/global-users”.

Click “Add Item”.

Name this new pool “global-pool” and add then select “Add Item” with the following pool member: 54.208.44.177. Change the Load Balancing Mode to “Static-Persist”, then click Continue.

Click “Continue”. Now set the Load Balancing Rule Score to 90. This allows the first load balancing rule, specific to EU users, to be returned as the only answer for users of that region unless the regional servers are unhealthy. Note: The rule with the highest score is returned. When two or more rules match and have the same score, answers for each rule is returned. Although there are legitimate reasons for doing this, matching more than one rule with the same score may provide an unanticipated outcome.

Now click "Apply", “Apply”, and “Continue”. Click the final “Apply” to create the new DNS Zone Resource Record Set.

Now click “Apply” to the DNS Zone configuration to commit the new Resource Record.

Click “Save and Exit” to finalize everything and complete the DNS Zone configuration!

To view the status of the services that were just created, navigate to DNS Management > Overview > DNS Load Balancers > app-dns-rule.

Clicking on the rule “eu-pool”, you can find the status for each individual IP endpoint, showing the overall health of each pool’s service that has been configured.

With the DNS Load Balancing rule configured to connect two separate regions, when one of the primary sites goes down in the eu-pool users will instead be directed to the global-pool. This provides reliability in the context of site failover that spans regions. If data privacy is also a requirement, additional rules can be configured to support more sites in the same region.

DNS LB for Active-Passive Sites

In the previous scenario, two members are configured to be equally active for a single location. We can change the weight of the pool members so that of the two only one is used when the other is unhealthy or disabled. This creates a backup/passive scenario within a region.

Navigate to DNS Load Balancer Management > DNS Load Balancers. Go to the service name "app-dns-rule", then under Actions, select Manage Configuration. Click Edit Configuration for the DNS rule.

Go to the Load Balancing Rules section, and Edit Configuration.

On the Load Balancing Rules order menu, go to Actions > Edit for the eu-pool Rule Action.

In the Load Balancing Rule menu for eu-pool, under the section Action, click Edit Configuration.

In the rule for eu-pool, under Pool Type (A) > Pool Members click the Edit action

In the IP Endpoint section, change the Load Balancing Priority to 1, then click Apply.

Change the Load Balancing Mode to Priority, then exit and save all changes by clicking Continue, Apply, Apply, and then Save and Exit.

DNS LB for Disaster Recovery

Unlike with backup/standby where failover can happen automatically depending on the status of a service's health, disaster recovery (DR) can either happen automatically or be configured to require manual intervention. In the following two scenarios, I'll show how to configure manual DR failover within a region, and also how to manual failover outside the region.

To support east/west manual DR failover within the EU region, use the steps above to create a new Load Balancing Rule with the same label selector as the EU rule (eu-pool) above, then create a new DNS LB pool (name it something like eu-dr-pool) and add new designated DR IP pool endpoints.

Change the DR Load Balancing Rule Score to 80, and then click Apply.

On the Load Balanacing Rules page, change the order of the rules and confirm that the score is such that  it aligns to the following image, then click Apply, and then Save and Exit.

In the previous active/standby scenario the Global rule functions as a backup for EU users when all sites in EU are down. To force a non-regional failover, you can change F5 XC DNS to send all EU users to the Global DNS rule by disabling each of the two EU DNS rule(s) above.

To disable the EU DNS rules, Navigate to DNS Load Balancer Management > DNS Load Balancers, and then under Actions, select Manage Configuration. Click Edit Configuration for the DNS rule.

Go to the Load Balancing Rules section, and Edit Configuration.

On the Load Balancing Rules order menu, go to Actions > Edit for the eu-pool Rule Action.

In the Load Balance Rule menu for eu-pool, under the section Action, click Edit Configuration.

In the top section labeled Metadata, check the box to Disable the rule. Then click Continue, Apply, Apply, and then Save and Exit.

With the EU DNS LB rules disabled, all requests in the EU region are served by the Global Pool. When it's time to restore regional services, all that's needed is to re-enter the configuration rule and uncheck the Disable box to each rule.

DNS LB Fallback Pool (Failsafe)

The scenarios above illustrate how to designate allternate pools both regional and global when an individual pool fails. However, in the event of a catastrophic failure that brings all service pools are down, F5 XC provides one final mechanism, the fallback pool. Ideally, when implemented, the fallback pool should be independent from all existing pool-related infrastructure and services to deliver a failsafe service.

To configure the Fallback Pool, navigate to DNS Management > DNS Load Balancer Management, then "Managed Configuration" of your DNSLB service.

Click "Edit Configuration", navigate to the "Fallback Pool" box and choose an existing pool. If no qualified pool exists, the option is available to add a new pool. In my case, I've desginated "global-poolx" as my failsafe fallback pool which already functions as a regional backup.

Best practice for the fallback pool is that it should be a pool not referenced elsewhere in the DNSLB configuration, a pool that exists on completely independent resources not regionally-bound.

DNS LB Health Checks and Observability

For sake of simplicity the above scenarios do not have DNS LB health checks configured and it's assumed that each pool's IP members are always reachable and healthy. My next article shows how to configure health checks to enable automatic failovers and ensure that users always reach a working server.

Conclusion

Using the Distributed Cloud DNS Load Balancer enables better performance of your apps while also providing greater uptime. With scaling and security automatically built into the service, responding to large volumes of queries without manual intervention is seamless. Layers of security deliver protection and automatic failover. Built-in DDoS protection, DNSSEC, and more make the Distributed Cloud DNS Load Balancer an ideal do-it-all GSLB distributor for multi-cloud and hybrid apps.

To see a walkthrough where I configure first scenario above for Geo-IP proximity, watch the following accompanying video.

Additional Resources

Next article: Using Distributed Cloud DNS Load Balancer health checks and DNS observability

More information about Distributed Cloud DNS Load Balancer available at:
https://www.f5.com/cloud/products/dns-load-balancer

Product Documentation:
DNS LB Product Documentation
DNS Zone Management

Updated Dec 28, 2023
Version 4.0

Was this article helpful?

No CommentsBe the first to comment