Professional Documents
Culture Documents
Big-Ip Dns (Previously GTM) : F5 Partner Technical Boot Camp
Big-Ip Dns (Previously GTM) : F5 Partner Technical Boot Camp
Big-Ip Dns (Previously GTM) : F5 Partner Technical Boot Camp
(previously GTM)
F5 Partner Technical Boot Camp
Written for TMOS v13.0
• Lesson 1: DNS Review and Deploying BIG-IP DNS
• Lesson 2: BIG-IP DNS Services
• Lesson 3: Global Server Load Balancing (GSLB)
Hosted DNS
Pros Cons
Pros Cons
Pros
66.163.171.12
9
66.163.171.129
66.163.171.129
Web server
What are the DNS will continue to resolve to a site, even if the site is down
limitations of
standard DNS?
No ability to “persist” if an application is stateful
Go ask
.com DNS
DNS LTM
www.subzone.domain.com domain.com
.com DNS server DNS server
domain.com
DNS server
Delegation Mode
LDNS
Is there a record for
www.domain.com?
66.163.171.129
66.163.171.129
Data Center
X
DNS LTM
App App
Servers Servers
72.68.171.103 66.163.171.129
Web server Web server www.subzone.domain.com domain.com
domain.com DNS server
DNS server
Authoritative or Inline Mode
Data Center
DNS LTM
zone.domain.com
Servers
domain.com domain.com
DNS server
Authoritative Screening (Inline)
LDNS
Resolved DNS
request First, BIG-IP DNS checks
In Authoritative
wide Mode,
IPs, and if matched,
BIG-IP to
resolves DNStheisbest
inline to
answer
existing DNS Servers Finally, BIG-IP DNS
forwards to existing
DNS servers
Data Center
DNS LTM
BIG-IP DNS listener
intercepts all DNS requests
zone.domain.com
Servers
Next, BIG-IP DNSdomain.com domain.com
DNS server
checks name against
DNS Express zones
• Lesson 1: DNS Review and Deploying BIG-IP DNS
• Lesson 2: BIG-IP DNS Services
• Lesson 3: Global Server Load Balancing (GSLB)
F5 DNS Services Vision
10.X
por
DN
SS t
EC
wit
Ge h rea
o- l -t i
Comprehensive GSLB
loc me
a ti o n sig
nin
sup
po r g
t
DN
Sp
ro t
oco
l va
DN li d a
S Exp tion
re ss /D
11.0
NS
DN p rox
S6- y
DNS delivery
>4
s
High performance
upp
IP A ort
ny c
ast
su p
por
t
Per
-pa
c ket
F5 DNS – GSLB to DNS Delivery
i Ru
Hig l es
h per
DN
S
f orm beh
11.1 / 11.2
a vi
DN anc
eD or
SS
High performance
EC NS
v C
caching and resolving
alid ach
a t io n i ng
+R
eso
lve
r
Hig
h spe
ed
log
Ad gi n
11.3
van g/
ce d re Qu
ery
DD
por
t a nd
oS i ng r esp
thr s up o nse
Visibility and reporting
esh por
o ld t
ale
rtin
DN g
Sm
enu
rev
AX am
FR p
Fro
m DN
Sta SE
ti cz xpr
o ne ess
11.4 / 11.5
DN
SS
enhancements.
Off EC
-bo
x s ig
and service provider
usa n in
g g
Ease of use deployment
Zo e fo
ne r ge
fo r o lo
wa cat
rde
r io n
BIG-IP GTM is Now BIG-IP DNS
BIG-IP DNS
BIG-IP GTM
BIG-IP v12.0
DNS DDoS Attacks are Common
80%
70%
70%
60%
50%
40% 37%
31%
30%
20% 17%
9% 10%
10%
0%
HTT DNS SIP IRC
DNS Express
DNS Express
DNS
Answer Manage
DNS DNS
BIG-IP Query Records
Answer Answer
DNS DNS
Query Query Admin
OS Auth
Roles
Answer Answer
DNS DNS
Query Query Dynamic
NIC DNS
DHCP
DNS Express vs. DNS Caching
• Good
• Saves internal users from
constantly resolving
• Bad
• Easily beaten by DDoS attacks
varying DNS query each request
Order of Precedence – Answers to DNS Query
DNS Listener
DNS Listener
DNS Listener
What’s GSLB?
DNS pool
VS: 73.37.1.11:21
VS: 205.33.1.1:80
Enable or disable
virtual server discovery
Add virtual
servers manually
F5 iQuery Protocol
big3d_install
DNS Exercise 2: Create Data Centers and Servers
A virtual server is an
IP address and port
representing an application
The IP address is
used in the DNS
The port is required
resolution process
for monitoring
Primary DC Secondary DC
Add Virtual Servers to Server Objects
VS: 73.37.1.1:21
Server Servers
Primary DC
Add Virtual Servers Manually
Wide IP
Load Balancing
Pool Pool
Load Load
Balancing Balancing
Wide IP Topology
Three
methods?
Name of Wide IP
must match FQDN