Blocking reverse lookup queries for private ips

Matus UHLAR - fantomas uhlar at fantomas.sk
Thu Nov 24 09:36:46 UTC 2016


On 24.11.16 13:57, Sachin Patil wrote:
>I have changed option - "forward only;" to "forward first;" and it has
>enabled empty zones.
>I can see request for private ips not going over internet using tcpdump.
>
>This configurations works, but is this good configuration for forward only
>dns server or will there be any problems related caching etc with this conf.

no, the good configuration is if you do the recursion yourself, without
forwarding to google.

-- 
Matus UHLAR - fantomas, uhlar at fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
He who laughs last thinks slowest. 


More information about the bind-users mailing list