Last Modified: Aug 05, 2026
Affected Product(s):
BIG-IP DNS
Known Affected Versions:
21.1.0, 21.1.0.1
Opened: Jul 01, 2026 Severity: 3-Major
DNS Response Policy Zone (RPZ) policies are not evaluated when the upstream DNS server returns error response codes such as SERVFAIL, NOTAUTH, REFUSED, NOTIMPL, or FORMERR. The error response is passed through to the client without RPZ policy enforcement.
RPZ policy actions (such as NXDOMAIN, NODATA, walled garden, or local data) are not enforced for queries where the upstream server returns an error response. This creates a gap in DNS firewall coverage, allowing blocked domains to bypass RPZ when the upstream server is returning errors
- BIG-IP DNS configured with a validating cache resolver and RPZ enabled - RPZ action set to "given" or any other configured action - Upstream DNS server returns an error response code (SERVFAIL, NOTAUTH, REFUSED, NOTIMPL, or FORMERR) for a domain that has an RPZ policy record
None
None