Re: Allowing recursion for just specific zones

2010-05-12 Thread Brian Candler
> Or else set up secure proxies and disallow all DNS resolution (an > empty root zone). I'm not sure what you mean by "secure proxies". Do you mean some non-BIND software capable of forwarding and filtering DNS queries/responses? If so, do you have anything particular in mind? Thanks, Brian. __

Re: Allowing recursion for just specific zones

2010-05-11 Thread Brian Candler
On Mon, May 10, 2010 at 11:54:57AM -0700, Chris Buxton wrote: > One strategy would be to set up a view that matches recursive queries > only. Set allow-query to none at the view, then set it any (or > whatever) in each zone of type forward or stub. Thank you Chris. Unfortunately, allow-query is r

Allowing recursion for just specific zones

2010-05-10 Thread Brian Candler
Hello, I am trying to configure a bind9 view to allow recursion just for certain domains. (This is bind-9.2.4-16.EL4 under RHEL4). In fact, it doesn't even have to be real recursion, just forwarding to an upstream recursive nameserver. The point is that the clients are only authorised to look up