Bug ID 2431857: BIG-IP DNS DNSSEC AXFR response incorrectly emits OPT pseudo-record in the Answer section, causing malformed zone-transfer data

Last Modified: Aug 30, 2026

Affected Product(s):
BIG-IP DNS(all modules)

Known Affected Versions:
17.5.1.6, 17.5.1.8

Opened: Jul 20, 2026

Severity: 2-Critical

Symptoms

DNS clients or packet analysers misinterpret the DNS responses

Impact

Malformed DNS responses from the DNS server

Conditions

- BIGIP DNS configured with DNSX as a secondary - BIND or upstream DNS acts as a primary - DNSSEC zone configuration is active for the zone in question - AXFR request received from client for the configured zone

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips