security and allow-query and/or acl

johnny at n0sq.net johnny at n0sq.net
Sat Sep 20 00:05:39 UTC 2003


I wanted to ask about the proper use of allow-query. I read that this should 
be set up to allow queries only from local machines on my network. What are 
the pros and cons for doing that? Would this prevent my external slaves 
from being able to resolve my domain? My guess is that my external slaves 
only need to be able to perform a zone transfer? If allow-query should be 
set up to deny all queries from outside my domain, would an acl be a better 
choice than using allow-query?


More information about the bind-users mailing list