Bug ID 2326721: DNS NXDOMAIN Query DoS vector statistics not updating for NXDomain responses

Last Modified: Jul 28, 2026

Affected Product(s):
BIG-IP AFM(all modules)

Fixed In:
21.1.0.1, 21.0.0.3, 17.5.1.8, 17.1.3.4

Opened: Jun 08, 2026

Severity: 3-Major

Symptoms

When Device/Profile DoS protection is configured with the DNS NXDOMAIN Query vector, the DoS statistics (stats, drops, and attack count) remain at zero, even when NXDomain responses are received from the server

Impact

DNS NXDOMAIN attack detection and mitigation are ineffective. The system fails to count or drop NXDomain-based attack traffic, leaving it vulnerable to DNS NXDOMAIN flood attacks

Conditions

DoS protection is configured for the device/profile using the DNS NXDOMAIN query vector, along with an LTM virtual server employing the UDP protocol and a backend DNS server that returns NXDomain responses

Workaround

Configure the DNS profile for the Virtual Server

Fix Information

The issue is fixed

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips