Scaling and securing every environment helps protect your business from site outages and improves DNS and application performance. Securing DNS infrastructures from the latest distributed denial-of-service (DDoS) attacks and protecting DNS query responses from cache-poisoning redirects will help keep your business online and viable. But to fully achieve these goals, you need efficient ways to monitor DNS infrastructure and application health and to scale on demand to meet exact requirements.
F5® BIG-IP® DNS (formerly BIG-IP® Global Traffic Manager™) distributes DNS and user application requests based on business policies, data center and cloud service conditions, user location, and application performance. The BIG-IP platform delivers F5’s high-performance DNS services with visibility, reporting, and analysis; hyperscales and secures DNS responses geographically to survive DDoS attacks; delivers a complete, real-time DNSSEC solution; and ensures high availability of global applications in all hybrid environments.
Hyperscale DNS up to 100 million RPS with a fully loaded chassis
BIG-IP DNS hyperscales authoritative DNS up to 100 million query responses per second (RPS) and controls DNS traffic. It ensures that users are connected to the best site and delivers on-demand scaling for DNS and global apps.
Protect against DNS attacks and ensure availability
Ensure DNS and application availability and protection during DNS DDoS attacks or volume spikes. In addition, mitigate DNS threats by blocking access to malicious IP domains.
Improve global application performance
Send users to the site with the best application performance based on application, geolocation, business, and network conditions.
Deploy flexibly, scale as you grow, and manage your network efficiently
BIG-IP DNS delivers flexible global application management in virtual and cloud environments. The web-based UI provides easy DNS configuration with centralized menus; advanced logging, statistics, and reporting; and a single point of control for your DNS and global app delivery requirements.
BIG‑IP DNS delivers hyperscale performance that can handle even the busiest sites. When sites have a volume spike in DNS queries due to legitimate requests or DDoS attacks, BIG-IP DNS manages requests with multicore processing and F5 DNS Express™, dramatically increasing authoritative DNS performance up to 50 million RPS to quickly respond to all queries.
This helps your organization provide the best quality of service (QoS) for your users while eliminating poor application performance. DNS Express improves standard DNS server functions by offloading DNS responses as an authoritative DNS server. BIG-IP DNS accepts zone transfers of DNS records from the primary DNS server and answers DNS queries authoritatively.
Benefits and features of multicore processing and DNS Express include:
• High-speed response and DDoS attack protection with in-memory DNS
• Authoritative DNS replication in multiple BIG-IP or DNS service deployments for faster responses
• Authoritative DNS and DNSSEC in virtual clouds for disaster recovery and fast,secure responses
• Scalable DNS performance for quality of app and service experience
• The ability to consolidate DNS servers and increase ROI
In cases of very high volumes for apps and services or a DNS DDoS attack, BIG-IP DNS hyperscales in Rapid Response Mode (RRM) up to 100 million RPS. It extends availability with unmatched performance and security—absorbing and responding to queries at up
to 200 percent of the normal limits. See page 13 for performance metrics and details.
DNS latency can be reduced by enabling a DNS cache on BIG-IP DNS and having it respond immediately to client requests. BIG-IP DNS can consolidate the cache and increase the cache hit rate. This reduces DNS latency up to 80 percent, with F5 DNS caching reducing the number of DNS queries for the same site. When used in hardware on the F5 VIPRION platform, DNS caching hyperscales for ultimate query response performance. In addition to caching, BIG-IP DNS allows the device to do its own DNS resolving without requiring the use of an upstream DNS resolver.
Caching profiles available to select for multiple caches include:
• Transparent cache
• BIG-IP DNS site between client and DNS internal/external
• Hot cache
• Caching resolver
• No cache response so that BIG-IP DNS sends out the request with the response coming back for resolving and caching
• Validating caching resolver
BIG-IP DNS supports all common DNS deployments that are either authoritative or local resolver DNS. Specific zone requests not cached are forwarded to name servers for faster DNS resolving, allowing users to receive expedient responses.
BIG-IP DNS reduces the average DNS response time and latency for mobile and desktop devices from an average of 300 milliseconds (ms) and 100 ms respectively to as little as 15 ms, depending on workloads.
DNS denial-of-service attacks, cache poisoning, and DNS hijacking threaten the availability and security of your applications. BIG-IP DNS protects against DNS attacks and enables you to create polices that provide an added layer of protection for your applications and data.
DNS attack protection features include:
DNS DDoS, cache poisoning of LDNS, and other unwanted DNS attacks and volume spikes can cause DNS outage and lost productivity. These attacks and traffic spikes increase volume dramatically and can take down DNS servers.
BIG-IP DNS, with security, scale, performance, and control functionality, provides DNS firewall benefits. It shields DNS from attacks such as reflection or amplification DDoS attacks and other undesired DNS queries and responses that reduce DNS performance. In addition, you can mitigate complex DNS security threats by blocking access to malicious IP domains with Response Policy Zones. With BIG-IP DNS, you can install a third-party domain filtering service such as SURBL or Spamhaus and prevent client infection or intercept infected responses to known sources of malware and viruses. F5 DNS firewall services reduce the costs of infection resolution and increase user productivity.
Lower your risk of malware and virus communication and mitigate DNS threats by blocking access to malicious IP domains with a domain reputation service such as SURBL or Spamhaus.
F5 DNS firewall services include:
*Requires provisioning BIG-IP Advanced Firewall Manager™ to access functionality.
BIG-IP DNS keeps apps available with firewall services protecting DNS infrastructure from highvolume attacks and malformed packets.
With BIG-IP DNSSEC support, you can digitally sign and encrypt your DNS query responses. This enables the resolver to determine the authenticity of the response, preventing DNS hijacking and cache poisoning. In addition, receive all the benefits of global server load balancing while also securing your DNS query responses. Alternatively, if a zone has already been signed, BIG-IP DNS manages static DNSSEC responses for higher performance.
Many IT organizations have or want to standardize on FIPS-compliant devices and secure DNSSEC keys. You can use BIG-IP DNS with FIPS cards that provide 140-2 support for securing your keys. In addition, BIG-IP DNS integrates and uses hardware security modules (HSMs) from Thales for implementation, centralized management, and secure handling of DNSSEC keys, reducing OpEx and delivering consolidation and FIPS compliance.
For DNS administrators who want to delegate to other secure sub-domains, BIG-IP DNS allows easy management of DNSSEC as a top-level domain, becoming a parent zone.
In most networks, DNS resolvers offload DNSSEC record requests and crypto calculations to validate that the DNS response being received is correctly signed. DNSSEC responses coming into the network require high CPU loads on DNS resolving servers.
With BIG-IP DNSSEC validation, administrators can easily offload and validate DNSSEC on the client side using BIG-IP DNS for resolving. This results in superior DNS performance and a dramatic increase in the site response to users.
BIG‑IP DNS offers global application availability and sophisticated health monitoring that support a wide variety of application types, giving organizations the flexibility to adapt quickly and stay competitive.
These global availability and health monitoring features include:
• Global load balancing—BIG-IP DNS provides comprehensive, high-performance application management for hybrid environments.
• Dynamic ratio load balancing—BIG-IP DNS routes users to the best resource based on site and network metrics (for example, based on the number of hops between the client and the local DNS).
• Wide area persistence—To ensure user connections persist across apps and data centers, BIG-IP DNS synchronizes data, propagates local DNS, and maintains
session integrity.
• Geographic load balancing—BIG-IP DNS includes an IP database identifying location at the continent, country, and state/province level to connect users to the closest app or service for the best performance.
• Custom topology mapping—With BIG-IP DNS, organizations can set up custom topology maps. By defining and saving custom region groupings, you can configure topology based on intranet app traffic policies that match your internal infrastructure.
• Infrastructure monitoring—BIG-IP DNS checks entire infrastructure health, eliminating single points of failure and routing app traffic away from poorly performing sites.
BIG‑IP DNS ensures users are always connected to the best site.
(1) User queries local DNS to resolve domain, and local DNS queries BIG‑IP DNS.
(2) BIG‑IP DNS uses metrics collected for each site and identifies the best server.
(3) BIG‑IP DNS responds to local DNS with IP address.
(4) User is connected to site.
BIG-IP DNS improves the application experience by intelligently monitoring the availability of resources. It expands application resilience by flexibly selecting and using the best available BIG-IP solutions for health monitoring. BIG-IP DNS reduces application downtime and enables easy availability with multiple settings in application monitoring.
Today’s sophisticated applications require intelligent health checks to determine availability. Instead of relying on a single health check, BIG‑IP DNS aggregates multiple monitors so that you can check the application state at multiple levels. This results in the highest availability, improves reliability, and eliminates false positives to reduce management overhead.
BIG‑IP DNS provides pre-defined, out-of-the-box health monitoring support for more than 18 different applications, including SAP, Oracle, LDAP, and mySQL. BIG‑IP DNS performs targeted monitoring of these applications to accurately determine their health, reduce downtime, and improve the user experience.
In addition to performing comprehensive site availability checks, you can define the conditions for shifting all traffic to a backup data center, failing over an entire site, or controlling only the affected applications.
Managing a distributed, multiple-site network from a single point is an enormous challenge. BIG-IP DNS provides tools that give you a global view of your infrastructure with the means to manage the network and add polices to ensure the highest availability for your businesscritical applications. Features include:
Reduce DNS delivery deployment time with centralized and easy-to-find configuration and management sequences.
DNS health monitor
The DNS health monitor available in BIG-IP DNS and BIG-IP Local Traffic Manager (LTM) monitors DNS server health and helps configure DNS based on reporting. The DNS health monitor detects whether the servers are operating at peak performance and helps in reconfiguring for optimal responses.
You can easily manage DNS and global app logging for fast network visibility and planning. High-speed logging of DNS queries and responses, syslog, and global server load balancing decision logs improve information on data to enable fast network recognition with quick, deep search and display.
BIG-IP DNS delivers advanced DNS statistics for administrators, with enhanced detailed data for profiles such as query type counts (A, CNAME, NS, RRSIG, AAAA, SRV, and “other” types) with requests, responses, and percentage counts. Stats are per profile and per device global count for fast visibility and capacity planning of DNS delivery infrastructure. DNS detail stats are viewable in DNS profile or in analytics reporting.
F5 Analytics provides advanced DNS reporting and analysis of applications, virtual servers, query names, query types, client IPs, top requested names, and more for business intelligence, capacity planning, ROI reporting, troubleshooting, performance metrics, and tuning, enabling maximum optimization of the DNS and global app infrastructure.
Administrators can easily manage DNS using analytics with advanced reporting and analysis of actions for fast visibility of DNS delivery and infrastructure.
Enterprise Manager can help you significantly reduce the cost and complexity of managing multiple F5 devices. You gain a single-pane view of your entire application delivery infrastructure and the tools you need to reduce deployment times, eliminate redundant tasks, and efficiently scale your infrastructure to meet your business needs.
BIG-IP DNS is designed to fit into your current network and into your plans for the future. Integration features include:
BIG-IP DNS and IP Anycast integration distributes the DNS request load by directing single IP requests to multiple local devices.
BIG-IP DNS services deliver query response per second (RPS) with high performance scalability. The table below lists many BIG-IP platforms with DNS Express enabled for authoritative DNS query response with the maximum capabilities per platform.
BIG-IP DNS Virtual Edition is available in increments of 250,000 RPS. For 5050s and above, Rapid Response Mode (RRM—see page 2) delivers up to 200 percent of normal max query RPS when turned on. See F5 Sales or reseller for details.