BIG-IP DNS

BIG-IP DNS’ role in the F5 Application Delivery and Security Platform (ADSP) enables your DNS and Global Server Load Balancing (GSLB) infrastructure to deliver a unified, scalable, intelligent framework for application delivery and security, for fast, secure applications across environments.

See buying optionsRead the data sheet

Scaling, Securing and Optimizing DNS

F5 ADSP maximizes application availability and performance, and provides BIG-IP DNS real-time traffic steering and GSLB through unified management and intelligent orchestration. It hyperscales and secures your infrastructure during high query volumes and DDoS attacks, ensuring reliable performance across hybrid and multicloud environments.

Unmatched DNS performance

Hyperscale up to 100 million responses per second (RPS) to manage rapid increases in DNS queries. With a feature set that includes multicore scalability, DNS Express, and IP Anycast integration, DNS delivery can handle millions of DNS queries and ensures top application performance for users.

  • 100m RPS Performance - BIG-IP DNS hyperscales authoritative DNS up to 100 million query responses per second (RPS), ensuring that users connect to the best site, and delivers on-demand scaling for DNS and global apps. DNS Express improves standard DNS functions by offloading DNS responses and scaling from hundreds of thousands to more than 50 million RPS.

  • DNS On-Demand Scaling - Deploy on-demand scaling with rate limit and object limit capacity as desired to BIG-IP DNS and GSLB.

  • Global Performance in the Cloud and On Premise - Direct users to servers that will deliver the fastest, most reliable connection based on business policies, user locations and app/server performance.

Secure DNS is critical

Total security is necessary for every application because applications are the center of attention for both bad actors and legitimate users. A poorly secured network can have damaging consequences, costing customers and revenue. BIG-IP DNS services provide DevOps-friendly agility with the scale, security depth, and investment protection needed for both established and emerging apps.

  • DNS Firewall/DDoS - Can be combined with BIG-IP AFM to provide extensive security, including shielding DNS from volumetric DDoS attacks such as UDP floods or amplification DDoS attacks.

  • DNSSEC - Protect LDNS servers from cache poisoning and man-in-the-middle attacks with real-time DNSSEC.

  • DoH/DoT - BIG-IP DNS decrypts and resolves DNS queries over HTTPS (DoH) without impacting RPS. DNS over TLS (DoT) ensures that DNS requests and responses are not tampered with or forged via on-path attacks.

Enhance caching and resolving to increase scalability

DNS latency can be reduced by enabling a DNS cache on BIG-IP DNS and having it respond immediately to client requests. This consolidates the cache and increases the cache hit rate, reducing DNS latency up to 80 percent. In addition to caching, BIG-IP DNS allows the device to do its own DNS resolving without requiring the use of an upstream DNS resolver.

  • Cache Consolidation - Latency and response time reduced by up to 80%.

  • DNS Load Distribution - IP Anycast integration distributes the DNS request load and directs single IP requests to multiple local devices.

  • Location-Based Routing - Routes clients to the nearest data center with geolocation-based load balancing for the best user experience.

Simplify DNS network management

Networks are growing, both in scale and traffic demands, driving the need for improved availability for users and better access and management for administrators. BIG-IP DNS affords easy visibility and programmability, ensuring network architectures are easier to maintain.

  • Integration with current infrastructure - Communicate and integrate with network devices like SNMP agents, third-party caches, servers, routers, and load balancers to diagnose network endpoint health.

  • Flexible site options - Enable flexible site options including Active/Active, Active/Passive, or Active/DR Only.

  • Failover that ensures availability - Failover whole data centers or individual apps/servers to ensure users have uninterrupted access to the apps they need.

Product Overview

Hyperscale and protect DNS while optimizing global app delivery

DNS enables users to access services, making it one of the most important components in the network infrastructure. If DNS is unavailable, services won’t function properly. Service providers and enterprises need to build an optimized and secure DNS infrastructure with the ability to rapidly scale and deal with millions of service names and IP addresses. Improve the performance and availability of your global applications by sending users to the closest or fastest endpoint—whether that be a physical, virtual, or cloud environment with F5 global server load balancing (GSLB).

Cloud-Native

Available in cloud-native format as a CNF, F5 application services work the same way in the public and private cloud as they do in the data center.

See cloud-native options ›

Virtual Editions

BIG-IP VEs have the same features as those that run on F5 hardware—and you can deploy them on any hypervisor or select cloud provider.

See virtual options ›

Hardware

Both the BIG-IP family of devices and the VELOS chassis are purpose-built, powerful hardware that F5 software runs on.

See hardware options ›

Core Capabilities

The F5 hyperscale and secure DNS solution provides faster web browsing and reduced latency, improving user experience and leading to reduced churn and increased revenues. Visibility into DNS and these applications mean that their health, optimization, and protection can be maximized.

Superior DNS performance

Manages query responses with multicore scalability, handling spikes in DNS query volumes.

DNS security

Validates query requests, mitigates malicious communications, absorbs DDoS attacks, encrypts end to end with SSL, and more.

Reporting and analytics

Logging, reporting, and analytics - detailed DNS and GSLB data, statistics, and graphs for in-depth analysis.

Global server load balancing

Supports application requirements across data center and cloud environments while keeping apps available.

Continual monitoring and automated failover

Gives you the flexibility to shift traffic to a backup data center and fail over an entire site, or just control the affected apps.

DNS health monitor

Out-of-the-box health monitoring support for applications.

3G, 4G, and 5G 3GPP support

Supports NAPTR DNS nodes and services to drive faster service instantiation.

IPv6 and DNS64 support

Translates traffic for consumption by either IPv4 or IPv6 endpoints.

Platform Support and Integrations

Technology alliances

F5 application services integrate with major cloud providers and are available directly through marketplace offerings with variable PAYG or perpetual BYOL consumption options.

AWS Logo
Microsoft Azure Logo
Google Cloud Platform Logo
Alibaba Logo

[@portabletext/react] Unknown block type "span", specify a component for it in the `components.types` prop

Resources

Related Products

Deliver and Secure Every App
F5 application delivery and security solutions are built to ensure that every app and API deployed anywhere is fast, available, and secure. Learn how we can partner to deliver exceptional experiences every time.
Connect With Us