Forum Discussion

jjm1971's avatar
jjm1971
Icon for Altocumulus rankAltocumulus
Apr 09, 2020

Enable External DNS Resolution on BIG-IP DNS

I have set up DNS Express on a BIGIP DNS, zone transfers and internal DNS resolution using the BIGIP works as expected. I also need to provide DNS resolution for external urls using the BIGIP, so I have set up a DNS resolver cache, with root hints added. I can only use certain external DNS servers (eg 1.1.1.1 / 8.8.8.8) which are allowed through firewalls and this works fine most of the time. What I have seen is that if these fail to resolve an external url they can respond with other root DNS servers, which the BIGIP then attempts to query to resolve the url. Issue is that these are not on the list of allowed IPs on the firewall so the resolution fails.

 

Is this a way to provide external resolution or is there a better solution?

2 Replies

  • You need to allow rule in firewall port 53 tcp n UDP. There is no other way...

    Thanks​

    • jjm1971's avatar
      jjm1971
      Icon for Altocumulus rankAltocumulus

      Hi Samir, it's not a firewall issue. The correct firewall rules are in place however they only allow access to a restricted list of external DNS servers. The question I have posted is around whether I have implemented the correct solution on the BIGIP DNS to provide external DNS resolution.

       

      John