Subject / Proposed Feature: Implement a native, strict fail-closed boundary control on F5XC DNS Load Balancers to silently drop, block, or return NXDOMAIN (RCODE 3) or REFUSED (RCODE 5) responses for unmatched geolocations when no fallback pool is defined.
The Current Limitation: The F5XC DNS engine currently fails open on unmatched geolocations, cascading the query down the evaluation chain to resolve against the final rule's pool IP, effectively bypassing intended perimeter restrictions.
The Requested Functionality: Introduce a default-deny, Zero-Trust perimeter policy on the DNS Load Balancer that intercepts and terminates unmatched geolocation queries at the ingress edge using custom drop or refuse responses.
The Business & Security Use Case: Uncontrolled IP disclosure exposes customer critical infrastructure to active nation-state reconnaissance, invites edge-resource exhaustion via DNS reflection/amplification attacks, and creates severe non-compliance liabilities under strict localized data residency regulations.
The Expected Behavior: The DNS Load Balancer must enforce edge-isolation by instantly dropping unmatched queries or returning explicit policy-rejection codes, ensuring zero-visibility and zero-resource allocation for unauthorized sources.
The Impact of the Limitation: This structural fail-open vulnerability allows global threat actors to systematically map internal corporate topologies, completely neutralizes geolocation-based access perimeters, and leaks sensitive asset destinations.