@Adam_Forester not entirely sure if you were planning to update this great guide. Just two small observations after we upgraded to R80.30.
I know it's already in the thread here but maybe add to the PDF domains_tools CLI, that's a massive improvement from R80.10
And additionally we got caught out with some clusters that have been there for million years - there was a rule permitting DNS requests from gateway only on UDP and not UDP+TCP. That resulted in wsdnsd going into "blocked" state and causing a lot of domain resolution alerts in logs:
Basically those DNS responses that were marked as truncated over UDP would trigger TCP DNS lookup but since there was no rule permitting that, it simply died quietly and caused wsdnsd to go into blocked state for 44secs!
So it's a must "check" (domain-tcp) for FQDN and Updatable Objects that utilise DNS.
I run through all relevant SKs (sk120633, sk120558, sk90401) but none of them had it either
K