Bug ID 1216573: AFM Learning Domain issue when trying with many valid domains

Last Modified: Oct 09, 2024

Affected Product(s):
BIG-IP AFM(all modules)

Fixed In:
16.1.5

Opened: Jan 06, 2023

Severity: 3-Major

Symptoms

Trying with too many valid domains and not all these domains have entries created in the NXDOMAIN table when they are trying to do learning.

Impact

We will not be able to honor the legitimate DNS A query when an NXDOMAIN attack is detected.

Conditions

The NXDOMAIN vector is enabled be it at the device level, virtual server level, or at both levels.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips