Bug ID 807269: DNS Relay Proxy service does not recover to its former functional state in case of errors and/or service restart.

Last Modified: Apr 28, 2025

Affected Product(s):
APM-Clients APM(all modules)

Known Affected Versions:
7.1.8, 7.1.8.1, 7.1.8.2, 7.1.8.3, 7.1.8.4, 7.1.8.5, 7.1.9, 7.1.9.7, 7.1.9.8, 7.1.9.9

Fixed In:
7.2.2, 7.2.1.1

Opened: Jul 19, 2019

Severity: 3-Major

Symptoms

-- If DNS Relay Proxy encounters unrecoverable errors continuously, it becomes stuck in an inoperable state. -- DNS Split scope does not work when the service is in such a state.

Impact

DNS Relay Proxy service no longer intercepts/redirects/forwards DNS requests. In that case, DNS Split scope stops working.

Conditions

-- DNS resolution encounters a bottleneck, and the system has generated a lot of DNS queries in short period of time. In this case service may encounter unrecoverable error. -- VPN is established and DNS Relay Proxy service is restarted via Windows Service Control Manager.

Workaround

This defect has no workaround. There is no way to maintain the same VPN connection while getting the service back to its functional state upon service restart. However, in the case of DNS issues due to some unrecoverable error in DNS relay proxy service, a service restart operation ensures that DNS redirection in the service stops, and the system takes care of directing DNS traffic. Although split scopes may not work, the system ensures that at least basic DNS resolution is working. If the issue is a one-time occurrence, you can disconnect from the VPN and connect to the VPN again to get the service into a functional state.

Fix Information

Introduced a monitor for DNS Relay Proxy service. When the service is restarted, the VPN tunnel is reconnected and DNS exception rules are repopulated.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips