Forum Discussion

Eflamenco_28963's avatar
Eflamenco_28963
Icon for Nimbostratus rankNimbostratus
Sep 04, 2018

DNS and WAF on the same box

Dear Pros: I have a Bigip provisioned with DNS and WAF in the same box, When I add the vs_WAF as a wide ip "A record", the listener reply with the private IP from the vs_WAF, thats sound as a logical answer, as the listener is not aware of the public IP address I pretend to reply for DNS queries. Now my question is, What is my best bet to answer to DNS queries with the public IP address of vs_WAF configured as NAT in the firewall? note:The WAF´s public side is in the DMZ subnet of a Firewall. host--->LDNS---->Autoritative DNS--->Firewall--->[F5 DNS Listener + vs_WAF]--->NLB Private IP

 

I would like to avoid dealing with route domains with DNS and WAF in separate RD.