Stopping name server abuse

Barry Margolin barmar at alum.mit.edu
Mon Jun 25 15:34:19 UTC 2018


In article <mailman.79.1529899821.803.bind-users at lists.isc.org>,
 "Browne, Stuart" <Stuart.Browne at team.neustar> wrote:

> If you're filtering on an upstream device that can do that level of analysis 
> without hurting your network, then maybe, but once again, you're 
> double-processing every legitimate query; you're only moving the cost to a 
> different device.

An upstream firewall might already be parsing it, so telling it not to 
pass some of them through could be relatively cheap.

-- 
Barry Margolin
Arlington, MA


More information about the bind-users mailing list