Forum Discussion

John_Stewart_47's avatar
John_Stewart_47
Icon for Nimbostratus rankNimbostratus
Feb 11, 2009

DNS recursion

We have 4 GTM and 4 LTM in Internet environment.

 

 

Why would we want recursion enabled on our GTM's if we never want them to look up domains other than our own?

 

 

I noticed it is now off by default in 9.3.1, but it is on on our boxes. I would like to turn it off to make PCI scan happy.

 

 

Any thoughts?

 

 

1 Reply

  • My $.02: Leave recursion off if you can. This has been an issue for general DNS security for quite some time, so I personally think it's best to keep it disabled if at all possible.

     

    -Matt