Bug ID 1070737: AFM does not detect NXDOMAIN attack at virtual context when DNS cache is activated.

Last Modified: Jan 20, 2023

Bug Tracker

Affected Product:  See more info
BIG-IP AFM(all modules)

Known Affected Versions:
15.1.0,,,,,, 15.1.1, 15.1.2,, 15.1.3,, 15.1.4,, 15.1.5,, 15.1.6,, 15.1.7, 15.1.8,, 16.1.0, 16.1.1, 16.1.2,,, 16.1.3,,,

Opened: Dec 29, 2021
Severity: 3-Major


When the DNS cache is activated, the NXDOMAIN DoS vector does not increase for the virtual server context. As a result, NXDOMAIN flood attack is never detected/mitigated at the virtual server context. Note this does not happen with other vectors like DNS A query flood attack, only for NXDOMAIN.


NXDOMAIN flood attack is never detected/mitigated at virtual server context.


Issue is only seen When DNS cache is activated and for NXDOMAIN Dos Vector.



Fix Information


Behavior Change