Manual Chapter :
Common Elements for Listeners
Applies To:
Show VersionsBIG-IP APM
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
BIG-IP Analytics
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
BIG-IP Link Controller
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
BIG-IP LTM
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
BIG-IP PEM
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
BIG-IP AFM
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
BIG-IP DNS
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
BIG-IP ASM
- 17.1.1, 17.1.0, 17.0.0, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0
Common Elements for Listeners
Create listeners to identify
the DNS queries that BIG-IP DNS handles. The best practice is to create four listeners: one
with an IPv4 address that handles UDP traffic, and one with the same IPv4 address that
handles TCP traffic; one with an IPv6 address that handles UDP traffic, and one with the
same IPv6 address that handles TCP traffic.
DNS zone transfers use TCP
port
53
. If you do not configure a listener for TCP the
client might receive the error: connection refused or TCP
RSTs.
The best practice is to create
two listeners: one that handles UDP traffic and one that handles TCP traffic.
DNS zone transfers use TCP port
53
. If you do
not configure a listener for TCP the client might receive the error:
connection refused or TCP RSTs.
- On the Main tab, click.The Listeners List screen opens.
- On the Main tab, click.The Listeners List screen opens.
- On the menu bar, clickLoad Balancing.
- ClickCreate.The Listeners properties screen opens.
- Click the name of the listener you want to modify.
- From theProtocoldrop-down list, select eitherUDPorTCP.The listener uses the UDP or TCP protocol to listen for connections on the enabled VLANs. The default is UDP. Zone transfers require the TCP protocol.
- From theListenerlist, selectAdvanced.
- In theNamefield, type a unique name for the listener.
- In theNamecolumn, click the name of a listener you want to modify.
- In theDescriptionfield, identify the listener in a unique way.
- From theStatelist, selectDisabled.
- From theStatelist, selectEnabled.
- For the Destination setting, in theAddressfield, type the IP address previously used by the legacy DNS server.
- For the Destination setting, in theAddressfield, type the IP address on which BIG-IP DNS listens for network traffic.The destination is a self IP address on BIG-IP DNS.
- For the Destination setting, in theAddressfield, type an IPv4 address on which BIG-IP DNS listens for network traffic.
- For the Destination setting, in theAddressfield, type an IPv4 address on which the BIG-IP system listens for DNS queries.
- For the Destination setting, in theAddressfield, type an IPv6 address on which BIG-IP DNS listens for network traffic.
- For the Destination setting, in theAddressfield, type the same IP address you used for your UDP listener.
- For the Destination setting, in theAddressfield, type the floating IP address of VLANexternal. This is the IP address on which BIG-IP DNS listens for network traffic.
- For the Destination setting, in theAddressfield, type the IP address on which the system listens for network traffic.
- For the Destination setting, in theAddressfield, type the IP address on which the system listens for network traffic.For this example, type10.1.1.50.
- For the Destination setting, in theAddressfield, type the floating IP address you created previously. This allows either system in the redundant system configuration to handle DNS requests.
- For the Destination setting, in theAddressfield, type the IP address on which BIG-IP DNS listens for network traffic.The destination cannot be a self IP address on the system, because a listener with the same IP address as a self IP address cannot be advertised.
- For the Destination setting, in theAddressfield, type the IP address on which BIG-IP DNS listens for DNS queries.The destination is the IP address of a DNS server to which you want the listener to forward traffic.The destination must not match a self IP address on BIG-IP DNS.
- For the Destination setting, in theAddressfield, type the IP address on which BIG-IP DNS listens for access point name (APN) traffic.F5 Networks recommends that you assign a unique IP address, not a self IP address.
- For the Destination setting, in theAddressfield, type the self-IP address that is also the IP address of the DNS server that hosts the zone.
- For the Destination setting, in theAddressfield, type the IP address on which BIG-IP DNS listens for DNS queries.The destination is the IP address of a DNS server to which you want the listeners to route DNS queries.The destination must not match a self IP address on BIG-IP DNS.
- For the Destination setting, in theAddressfield, type the IPv4 address on which the BIG-IP system listens for DNS zone transfer requests for a zone hosted on a DNS server.
- For the Destination setting, in theAddressfield, type the IPv4 address on which the BIG-IP system listens for DNS zone transfer requests for a zone hosted on pool of DNS servers.
- For the Destination setting, in theAddressfield, type an asterisk (*).Use the asterisk when you want BIG-IP DNS to not only process and respond to wide IP requests, but also to forward DNS queries to network resources, such as other DNS servers.
- In theDestinationfield, type the self IP address on which the Link Controller listens for traffic.
- In theDestinationfield, type the self IP address on which the Link Controller listens for traffic.For this example, type10.10.10.1.
- For the Destination setting, in theAddressfield, type the self IP address on which the Link Controller listens for traffic from ISP 1.For this example, type10.20.10.1.
- From theService Portlist, select the service port on which the system listens for connections.
- From theVLAN Trafficlist, select one of the following options:All VLANsWhen you want this listener to handle traffic on all VLANs within the network segment.Use this option if BIG-IP DNS is handling traffic for the destination IP address locally. This option also applies when the system resides on a network segment that does not use VLANs.Enabled onWhen you want this listener to handle traffic on only the VLANs that you move from theAvailablelist to theSelectedlist.Disabled onWhen you do not want this listener to handle traffic on the VLANs that you move from theAvailablelist to theSelectedlist.
- From theVLAN Trafficlist, selectAll VLANs.
- From theVLAN Trafficlist, selectEnabled on, and then move the VLANS for which you want this listener to handle traffic from theAvailablelist to theSelectedlist.
- From theVLAN Trafficlist, selectDisabled on, and then move the VLANS for which you do not want this listener to handle traffic from theAvailablelist to theSelectedlist.
- From theSource Address Translationlist, selectNonewhen BIG-IP DNS does not use a source address translation pool for this listener.
- From theSource Address Translationlist, selectSNAT, and then, from theSNAT Poollist, select the pool BIG-IP DNS uses for source network address translation (SNAT).
- From theSource Address Translationlist, selectAuto Mapwhen you want BIG-IP DNS to use the self IP addresses as the translation addresses.
- If you are using SNATs on your network, from theSource Address Translationlist, selectSNAT.
- Optional: If you are using NATs on your network, for theAddress Translationsetting, select theEnabledcheck box.
- For theAddress Translationsetting, select theEnabledcheck box.
- Optional: If you are using port translation on your network, for thePort Translationsetting, select theEnabledcheck box.
- For thePort Translationsetting, select theEnabledcheck box.
- For theRoute Advertisementsetting, select theEnabledcheck box.
- From theAuto Last Hoplist, selectEnabled.
- From theAuto Last Hoplist, selectDisabled.
- From theLast Hop Poollist, selectNone.
- From theLast Hop Poollist, select a pool.
- From theServicelist, selectAdvanced.
- In the Service area, from theProtocollist, select eitherUDPorTCP.
- In the Service area, from theProtocollist, selectUDP.
- In the Service area, from theProtocollist, selectTCP.
- In the Service area, for theDNS Profilesetting, select thednsprofile.When the listener is defined from the BIG-IP LTM Virtual Server page, select theudp_gtm_dnsprofile.
- From theProtocol Profile (Client)list, select the profile you want to apply to a DNS query the listener receives from a client.
- From theProtocol Profile (Server)list, select a profile you want to apply to a DNS response the listener receives from a server.
- From theDNS Profilelist, select:dnsThis is the default DNS profile. With the defaultdnsprofile, BIG-IP DNS forwards non-wide IP queries to the BIND server on the BIG-IP DNS system itself.<custom profile>If you have created a custom DNS profile to handle non-wide IP queries in a way that works for your network configuration, select it.
- In the Service area, from theDNS Profilelist, accept the default profiledns.With the default profile BIG-IP DNS forwards non-wide IP queries to the BIND server on the system itself.
- In the Service area, from theDNS Profilelist, select eitherdnsor a custom DNS profile configured for DNS Express.
- In the Service area, from theDNS Profilelist, selectdns_zxfr(the custom profile you created to enable the BIG-IP system to process zone transfer requests).
- In the Service area, from theDNS Profilelist, select the custom DNS profile withZone Transferenabled.
- In the Service area, from theDNS Profilelist, select the custom DNS profile withZone Transferenabled, andUse BIND server on BIG-IPdisabled.
- In the Service area, from theDNS Profilelist, select a custom DNS profile configured for DNS caching.
- In the Service area, from theDNS Profilelist, select a custom DNS profile that is associated with a DNS Logging profile.
- In the Service area, from theDNS Profilelist, select a custom DNS profile configured with an AVR sampling rate.
- In the Service area, from theDNS Profilelist, select the profile you created to manage IPv6 to IPv4 address mapping.
- From theDefault Poollist, select the pool to which this listener forwards DNS queries.
- From theDefault Poollist, select the pool to which this listener forwards DNS zone transfer requests.
- From theDefault Persistence Profilelist, select the profile that defines how this listener handles persistent connections.
- From theFallback Persistence Profilelist, select the profile you want BIG-IP DNS to use when it cannot use the selectedDefault Persistence Profile.
- From theStatistics Profilelist, select the profile that defines how BIG-IP DNS handles iRules statistics.
- For theiRule Managementsetting, move the iRules you want to apply to this listener from theAvailablelist to theSelectedlist.
- ClickFinished.
- ClickUpdate.
- ClickRepeat.
- ClickCancel.
Create another listener with the same IPv4
address and configuration, but select
TCP
from the
Protocol
list. Then, create two more listeners, configuring
both with the same IPv6 address, but one with the UDP protocol and one with the TCP
protocol.