Field Call Dynamic DNS Infrastructure v11.2 (Slides)
Field Call Dynamic DNS Infrastructure v11.2 (Slides)
© F5 Networks, Inc.
CONFIDENTIAL 3
Agenda
© F5 Networks, Inc.
CONFIDENTIAL 4
Clients
© F5 Networks, Inc.
Video by https://www.dnssec-tools.org/
CONFIDENTIAL 6
https://www.dnssec-
tools.org/ Sponsored by:
DHS S&T
LE DNS
ATION
S
SECURE DN
SCALAB
GEOLOC
FAST FAST
DNS SERVICES
SCALABLE IP GEO DNSSEC
SECURE SECURE
HIGH PERFORMANCE DNS
HIGH PERFORMANCE DNS
AVAILABLE AVAILABLE
DNS DDoS PROTECTION BIG-IP
TMOS TMOS DNS DDoS PROTECTION
AVAILABILE GTM
AVAILABLE
DNS IPV6 to IPv4
DNS IPv6 to IPv4
GLOBAL AVAILABILITY
S
TMO
S
TMO
S
iRULES
TMO
iCONTROL
iAPPS © F5 Networks, Inc.
CONFIDENTIAL 9
Access Denied:
IPv6 to IPv4
http://f5.com
© F5 Networks, Inc.
CONFIDENTIAL 10
100ms
15ms
15ms BIG-IP
Global Traffic Manager
Cloud
Private Public
400ms = blink of an eye
Internal Clients
© F5 Networks, Inc.
CONFIDENTIAL 12
Simple DNSSEC:
• Protection from cache poisoning and reduce management costs
• Ensure trusted DNS queries with dynamically signed responses
• Implement BIG-IP GTM in front of existing DNS servers
© F5 Networks, Inc.
CONFIDENTIAL 13
RRSIG record covering is verified by (KSK) DNSKEY record is verified by DS record is signed by
isc.org/DNSKEY for isc.org for isc.org
Data Center
BIG-IP
Global Traffic Manager
Internal Clients
© F5 Networks, Inc.
CONFIDENTIAL 15
Data Center
DNS Servers
www.company.com
Clients LDNS
company.com
X A Q i
© F5 Networks, Inc.
CONFIDENTIAL 18
WHEN
DNS_REQUEST
TMOS
TMM Linux
Balancing
64 Express
DNSSEC
DNS Caching
iRules
DNS
Resolver
Load
GTM iRules
IPv4 / IPv6
TCP / UDP
DNS 64
BIND
GTM
DNS::RETURN
DNSSEC
iRules
Clients
64
© F5 Networks, Inc.
CONFIDENTIAL 19
© F5 Networks, Inc.
CONFIDENTIAL 20
© F5 Networks, Inc.
CONFIDENTIAL 21
DNS Profile
11.0 and 11.1 11.2
© F5 Networks, Inc.
CONFIDENTIAL 22
Datacenter
LB X 64 CR
Clients
© F5 Networks, Inc.
CONFIDENTIAL 24
© F5 Networks, Inc.
CONFIDENTIAL 25
Datacenter
LB X 64 CR
Clients
© F5 Networks, Inc.
CONFIDENTIAL 27
DNSSEC Validation
F5 DNS Services
• GTM & Delegation Internet Site
LB • Recursive DNS LB & Screening
X • DNS Express
64 • DNS 64
CR • DNS Caching + Resolver
V • DNSSEC Validation
Datacenter V
LB X 64 CR
Clients
© F5 Networks, Inc.
CONFIDENTIAL 29
© F5 Networks, Inc.
CONFIDENTIAL 30
© F5 Networks, Inc.
CONFIDENTIAL 31
© F5 Networks, Inc.
CONFIDENTIAL 32
© F5 Networks, Inc.
CONFIDENTIAL 33
Events
• Interop, May 7 – 10, Vegas
• Agility – July 23 – 26, NYC
• Blackhat – July 21 – 26, Vegas
• RSA – Feb. 2012, was a huge
success in leads and awareness
© F5 Networks, Inc.
CONFIDENTIAL 34
© F5 Networks, Inc.
CONFIDENTIAL 35
Questions?
To ask a question:
• Press *1 -or-
• Enter your question in the Q&A pod in the top of the LiveMeeting
screen
© F5 Networks, Inc.
CONFIDENTIAL 36
Questions:
• How do I obtain DNS Caching?
• What happens with DNS Vendors relationships related
to DNS Caching?
• How does DNSSEC validation affect performance?
• How do I scale the DNS infrastructure?
• When will we see stats and logging for DNS?
© F5 Networks, Inc.
CONFIDENTIAL
© 2011 F5 Networks, Inc. All rights reserved. F5, F5 Networks, the F5 logo, BIG-IP, ARX, FirePass, iControl, iRules, TMOS,
and VIPRION are registered trademarks of F5 Networks, Inc. in the U.S. and in certain other countries