Forum Discussion

Gregt_33960's avatar
Gregt_33960
Icon for Nimbostratus rankNimbostratus
Mar 09, 2009

DNS and BigIP LTM

Hello,

 

 

 

I have a clustered pair of LTM6400s that manage several pools of web servers for a a series of complex application environments. My network design basically has the web servers in various DMZ's outside the Firewall, and the Data Tier inside. The F5 is defined as the default GW for all web servers. My DNS server, has to remain on the side because of my customer requirements. I was wondering if there is a way to configure the F5 to act as a DNS server or forwarder for web servers; so I do not have to:

 

 

1) Manage several local host files

 

2) Punch big holes inbound on my Firewall for DNS for all the Web Servers

 

 

I am suspecting setting up a DNS server is out of the question, but certainly thinking that DNS forwarder functionality.

 

 

 

Thanks

 

Greg

5 Replies

  • Hi Greg,

     

    Yes when you go to System >> General Properties >> Device >> DNS

     

     

    There are entry areas for the BIND Forwarder Server List so the LTM can ACT like a DNS proxy. Thus the servers would point to the floating address or gateway that lives on the F5 for DNS resolution.

     

     

    Details of the configuration are in the BIGIP Network and System Management Guides on ask.f5.com

     

     

    Hope this helps

     

    CB

     

  • hi CB,

     

    it helped in my LTM now i am workin with Link Controller.

     

    is it possible to replace DNS with lc, without GTM module to resolve FQDN for my web-server and webmail server.

     

    reading theory, i have to use my local DNS for canonical name (i.e. Zone file).

     

    so is there any way to replace DNS with LC,without GTM module.

     

     

    Many Thanks,

     

    Kris~

     

  • Hi Kris,

     

     

    LC can only hand out IP addresses that it hosts, as opposed to GTM which can hand out anything you tell it to. So it depends on whether LC will have a virtual server for your web & webmail services.

     

     

    Denny
  • Hey CB,

     

     

    Thank you for the assistance... Looks like it is working.

     

     

     

    Greg
  • it seems from your suggestion that,

     

    LC is not capable for "A" record,it will take help with zone file (C-NAME).

     

    while GTM can take care of all the things..