cancel
Showing results for 
Search instead for 
Did you mean: 
Login & Join the DevCentral Connects Group to watch the Recorded LiveStream (May 12) on Basic iControl Security - show notes included.

Resolution Using a DNS Resolver Cache

mahir
Altostratus
Altostratus

I would like to configure my DNS box as a resolver. I have applied all the steps as described in the following link

https://devcentral.f5.com/s/articles/configuring-the-f5-big-ip-to-perform-name-resolution-using-a-dn...

except that I noticed that the GTM uses other public IP which I have not configured in the Root hits part knowing that I have specified two external public IPs that the GTM must consult to resolve. is there a way to tell the GTM does the resolution only from these two IP XXXXX YYYYY

4 REPLIES 4

NAG
Cirrostratus
Cirrostratus

Hi Mahir,

 

Private Root Hint server IPs are configured when the network is completely isolated from public networks. For example, Military networks,classified networks etc.

 

For the networks connected to Public internet, there is no need for defining private root hint servers as public root hint servers do the job pretty well.

 

Here are the list of default Root Hint servers:

https://www.iana.org/domains/root/servers

 

Based on your problem description, I think, the DNS resolver you are building is not for air-gap or classified networks which are disjointed from public internet.

 

If that is true, you need not configure root hint servers and leave it blank so it uses public root servers as it should.

 

Moreover, when you query for a public domain name, and network is connected to public internet in any way, you can only get a Authoritative answer from a public source(IP) .

 

Let me know if it is not clear enough.

 

Regards,

Nag

NAG
Cirrostratus
Cirrostratus

mahir
Altostratus
Altostratus

Hello NAG

 

thank you for your help and support. is there a way to configure my DNS resolver to use just one public ip for example 8.8.8.8 to respond to internal DNS queries.

 

 

today even if I configure my forwarded zone with 8.8.8.8 I still see that my GTM uses public root IP

 

best regards

Mahir

 

 

 

NAG
Cirrostratus
Cirrostratus

Hi,

 

On DNS Profile, 

 

Unhandled Query Actions :: allow

Use BIND Server on BIG-IP :: Disabled

Process Recursion Desired :: Disabled

 

Hope this helps,

Nag