Bug ID 534886: AFM Security checks were not being done for DNS over TCP

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
11.5.1 HF1, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.1 HF10, 11.5.1 HF11, 11.5.2 HF1, 11.5.3 HF1, 11.5.3 HF2, 11.5.4 HF1, 11.5.4 HF2, 11.5.4 HF3, 11.5.4 HF4, 12.1.0 HF1, 12.1.0 HF2, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
12.0.0, 11.6.0 HF6

Opened: Jul 23, 2015

Severity: 3-Major

Symptoms

We had disabled DNS Query Filtering and DNS DoS checks for DNS over TCP.

Impact

Query Filtering and DNS DoS feature was not present for DNS over TCP.

Conditions

DNS over TCP and either DNS DoS configured or DNS Query filtering configured.

Workaround

Use DNS over UDP.

Fix Information

We have now enabled DNS Query filtering and DNS DoS checks regardless of the L4 protocol.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips