Manual Chapter : Create a custom DNS profile to firewall DNS traffic

Applies To:

  • BIG-IP AFM

    17.5.1, 17.5.0, 17.1.2, 17.1.1, 17.1.0, 17.0.0, 16.1.6, 16.1.5, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.10, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0

Create a custom DNS profile to firewall DNS traffic

Ensure that you have a DNS security profile created (Security > Protocol Security > Security Profiles > DNS) before you configure this system DNS profile.

You can create a custom DNS profile to configure the BIG-IP system firewall traffic through the system.

  1. On the Main tab, click Local Traffic > Profiles > Services > DNS.

    The DNS profile list screen opens.

  2. Click Create.

    The New DNS Profile screen opens.

  3. In the Name field, type a unique name for the profile.

  4. In the General Properties area, from the Parent Profile list, accept the default dns profile.

  5. Select the Custom check box.

  6. In the DNS Traffic area, from the DNS Security list, select Enabled.

  7. In the DNS Traffic area, from the DNS Security Profile Name list, select the name of the DNS firewall profile.

  8. Click Finished.

Assign the custom DNS profile to the protected object that handles the DNS traffic that you want to firewall.