[aklug] Re: BIND9 and ACL support

From: Arthur Corliss <acorliss@nevaeh-linux.org>
Date: Wed Mar 26 2008 - 21:44:31 AKDT

On Wed, 26 Mar 2008, dhull wrote:

> I guess I sort of miss represented BIND9 in that last post. ACL support is in BIND9 which is what I'm using. What I meant to say is that I've never used ACL support. As far as I know anyone could have done anything they wanted to my DNS server. Assuming they new what they were doing.

At least bind 4 isn't still the standard. :-)

> I just locked it down so all anyone can do is access testing-linux.com. Including me.

Speaking of which, I should have mentioned with my example you'd have to add
the following lines to each of your authoritative zone stanzas:

   allow-query { any; };

to keep your zone publically accessible.

         --Arthur Corliss
           Live Free or Die
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Wed Mar 26 21:45:15 2008

This archive was generated by hypermail 2.1.8 : Wed Mar 26 2008 - 21:45:15 AKDT