Reject cached answers

Wael Shahin wael.shahin at gmail.com
Thu Feb 1 10:18:40 UTC 2007


Hello List,
how can I prevent the replies that non-clients can get from my DNS servers
Since we have an authoritative name servers, we can't allow query for 
specific ACLs, and am wondering if a third party can gather statistics 
somehow out of this
assume I have the IP address range 172.16.0.0/16 allowed for recursive and 
am allowing query for "any"
and a machine with the IP addresss 192.168.0.33 tryed nslookup or pinging 
google.com, then my server will reply withe the ip for google.com if it is 
cached, it is not recursive but it still replies

am i getting this right ?



More information about the bind-users mailing list