BIND performance may be poor if the DNS load originates from a small number of source IP addresses or ports.
If you are using Ubuntu and a CA certificate of key length 1024 and some unsupported ciphers,
after a NIOS upgrade, services that depend on the unsupported ciphers cease to work.
A downgrade from NIOS 9.0.x to NIOS 8.4.x is not supported. Auto-synchronization from NIOS 9.0.x to NIOS 8.4.x is not supported.
If there are Threat Protection members in your Grid for the 8.3 and later features (Grid Master Candidate test promotion, forwarding recursive queries to BloxOne Threat Defense Cloud, and CAA records), ensure that you upload the latest Threat Protection ruleset for these features to function properly.
Infoblox recommends that you enable DNS Fault Tolerant Caching right after you upgrade to NIOS
8.2.x and later and keep this feature enabled to handle unreachable authoritative servers. Note that enabling this feature requires a DNS service restart, which will clear the current cache. Therefore, if you enable this when you are trying to mitigate an ongoing attack on an authoritative server that is outside of your control, it will clear the DNS cache, which will magnify the issues that your system is experiencing.
During a scheduled full upgrade to NIOS 8.1.0 and later versions, you can use only IPv4 addresses for NXDOMAIN redirection. You cannot use IPv6 addresses for NXDOMAIN redirection while the
upgrade is in progress.
After a scheduled upgrade to NIOS 8.6.3 and later is complete, you must run the
update_rabbitmq_password
command on the Grid Master to get the Cloud DNS Sync service to be functional. Until that time, Route 53 synchronization does not start because the service has not been started.
After an upgrade to NIOS 8.6.3 and later, the Cloud DNS Sync service starts automatically on the Grid member that is assigned to the Route 53 synchronization groups.
After an upgrade to NIOS 8.6.3 and later, the Disable Default Search Path and the Additional Search Paths fields will no longer be displayed in the Add Active Directory Authentication Service >
Step 1 of 1 wizard.
If you upgrade to NIOS 8.6.3 or later, all IB-FLEX appliances or Grids that have the FLEX Grid Activation license or the MSP license will have the ReportingSPLA external attribute assigned automatically for supported Grid members.
After an upgrade to NIOS 8.6.3 and later, only 5% of allowed blocklist subscribers is supported for virtual DNS Cache Acceleration (vDCA).