Bug ID 2368593: DNS RPZ policies are not applied when upstream server returns error responses

Last Modified: Aug 05, 2026

Affected Product(s):
BIG-IP DNS(all modules)

Known Affected Versions:
21.1.0, 21.1.0.1

Opened: Jul 01, 2026

Severity: 3-Major

Symptoms

DNS Response Policy Zone (RPZ) policies are not evaluated when the upstream DNS server returns error response codes such as SERVFAIL, NOTAUTH, REFUSED, NOTIMPL, or FORMERR. The error response is passed through to the client without RPZ policy enforcement.

Impact

RPZ policy actions (such as NXDOMAIN, NODATA, walled garden, or local data) are not enforced for queries where the upstream server returns an error response. This creates a gap in DNS firewall coverage, allowing blocked domains to bypass RPZ when the upstream server is returning errors

Conditions

- BIG-IP DNS configured with a validating cache resolver and RPZ enabled - RPZ action set to "given" or any other configured action - Upstream DNS server returns an error response code (SERVFAIL, NOTAUTH, REFUSED, NOTIMPL, or FORMERR) for a domain that has an RPZ policy record

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips