Abour RRL and Best Practise

2020-11-26 Thread Onur GURSOY
Hello Everyone, Bind9 is a good product and benchmark. It has good documentation especially about vulnerabilities. I wonder one thing, nowadays, For brute force, reflection, ampliciation and etc. attacks, there is prevention which is name response rate limit (RRL). Question: What is the default v

About DNSSec-Validation=Yes and bind.keys

2020-11-12 Thread Onur GURSOY
Hello Everyone, I have some trouble about bin9 and dnssec When i set dnssec-validation to auto. My dns server is talking with google dns server (8.8.8.8 and 8.8.4.4) and when i set to dnssec-validation to yes it couldn't talk with google dns server. i have realized, there is no pre defined bind.key