Zone with access-list

Bill Becker bindboy at mailhost.iconn.net
Fri Aug 27 13:45:43 UTC 1999



This is ancient history, so i didn't reply to the list.  Catching up on my
mail...

> Edmund Lam wrote:
> > 
> > Can I set-up 2 identical zones each with different allow-query
> > address-match-list so that response can be based on the
> > query machine source IP address ???


On Mon, 2 Aug 1999, Michael Voight wrote:

> No.
> 
> Why?

There seem to be a lot of people who want to do this (responses to queries
based on source address).  The access-list method can't work, but it would
be nice to have some way of doing this.

One reason would be to serve phoney A records to known email address
harvesters.  They want the A record for www.your.dom and you answer with
127.0.0.1 or maybe with the address of www.ftc.gov.  I can also think of a
few legit reasons to have source-dependant responses, but in my case
they'd be excuses.

I already use ACLs to deny responses to spam-friendly sites, but wouldn't
it be nice if you could get them into trouble by directing them to places
they'd normally avoid? 

Anyway, there's a definite demand for this 'feature'.

Bill




More information about the bind-users mailing list