The procedure for signing a zone for which the NetScaler is configured as a DNS proxy server depends on whether the ADC owns a subset of the zone information owned by the back-end name servers. If it does, the configuration is considered a partial zone ownership configuration. If the ADC does not own a subset of the zone information, the NetScaler configuration for managing the back-end servers is considered a zone-less DNS proxy server configuration. The basic DNSSEC configuration tasks for both NetScaler configurations are the same. However, signing the partial zone on the NetScaler requires some additional configuration steps.
Note: The terms zone-less proxy server configuration and partial zone are used only in the context of the NetScaler appliance.
Important: When configured in proxy mode, the ADC does not perform signature verification on DNSSEC responses before updating the cache.
If you configure the ADC as a DNS proxy to load balance DNSSEC aware resolvers (servers), you must set the Recursion Available option while configuring the DNS virtual server. If a DNSSEC query arrives with Checking Disabled (CD) bit set, the query is passed on to the server with the CD bit retained. The response from the server is not cached.