Re: Blocking reverse lookup queries for private ips

2016-11-29 Thread Reindl Harald
Am 24.11.2016 um 12:40 schrieb Sachin Patil: I need to forward requests to google as I am using this as forwarding server. the question is *why* because there is no benefit but only problems and beware if you run a mailserver with RBL/URIBL which won't work with such a setup as you think

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Sachin Patil
This is typo - 'I want to forward reverse dns lookup queries for private ips to forwarders on my bind server.' Correct one is - I don't want to forward reverse dns lookup queries for private ips to forwarders. On Fri, Nov 25, 2016 at 2:07 AM, Juan Bernhard wrote: > > El 22/11/2016 a las 07:40 a

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Juan Bernhard
El 22/11/2016 a las 07:40 a.m., Sachin Patil escribió: Hello All, I want to forward reverse dns lookup queries for private ips to forwarders on my bind server. I have searched on internet and found I can have mapping to my private ips in ptr db records but I don't want this. I want to re

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Matus UHLAR - fantomas
On 25.11.16 00:02, Sachin Patil wrote: My bind setup only modifies response/resolved ips for certain domains, this is the only purpose of my setup (apart from caching). I don't have any private/local zones, thus I have kept it in forwarded mode. once again: you should only use forwarders when

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Sachin Patil
My bind setup only modifies response/resolved ips for certain domains, this is the only purpose of my setup (apart from caching). I don't have any private/local zones, thus I have kept it in forwarded mode. Best Regards, Sachin On Thu, Nov 24, 2016 at 5:23 PM, Matus UHLAR - fantomas wrote: > O

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Matus UHLAR - fantomas
On 24.11.16 13:57, Sachin Patil wrote: I have changed option - "forward only;" to "forward first;" and it has enabled empty zones. I can see request for private ips not going over internet using tcpdump. This configurations works, but is this good configuration for forward only dns server or wil

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Sachin Patil
I need to forward requests to google as I am using this as forwarding server. On Thu, Nov 24, 2016 at 3:06 PM, Matus UHLAR - fantomas wrote: > On 24.11.16 13:57, Sachin Patil wrote: > >> I have changed option - "forward only;" to "forward first;" and it has >> enabled empty zones. >> I can see r

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Matus UHLAR - fantomas
On 24.11.16 13:57, Sachin Patil wrote: I have changed option - "forward only;" to "forward first;" and it has enabled empty zones. I can see request for private ips not going over internet using tcpdump. This configurations works, but is this good configuration for forward only dns server or wil

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Sachin Patil
Hello Mark, Thank you very much for the reply. I have changed option - "forward only;" to "forward first;" and it has enabled empty zones. I can see request for private ips not going over internet using tcpdump. This configurations works, but is this good configuration for forward only dns serve

Re: Blocking reverse lookup queries for private ips

2016-11-23 Thread Mark Andrews
Automatic empty zones are not created when there is a forward only entry covering the zone name. Almost all the time it is someone trying to make internal reverse zones work and if the upstream server is correctly configured it will prevent the queries leaking to the Internet as a whole. You are

Re: Blocking reverse lookup queries for private ips

2016-11-22 Thread Sachin Patil
Sending this to bind list ... had only sent to Tony by mistake.. !! On Tue, Nov 22, 2016 at 5:45 PM, Sachin Patil <04sac...@gmail.com> wrote: > Hello Tony, > Thank you very much for the reply. > > I have configured bind in forward mode. > My conf file looks like - > > options { > > directory "/va

Re: Blocking reverse lookup queries for private ips

2016-11-22 Thread /dev/rob0
On Tue, Nov 22, 2016 at 10:57:00AM +, Tony Finch wrote: > Sachin Patil <04sac...@gmail.com> wrote: > > > I want to return nxdomain for any private ip reverse lookup. > > BIND does this by default. Look for "built-in empty zones" in > https://ftp.isc.org/isc/bind9/cur/9.11/doc/arm/Bv9ARM.ch06.

Re: Blocking reverse lookup queries for private ips

2016-11-22 Thread Tony Finch
Sachin Patil <04sac...@gmail.com> wrote: > I want to return nxdomain for any private ip reverse lookup. BIND does this by default. Look for "built-in empty zones" in https://ftp.isc.org/isc/bind9/cur/9.11/doc/arm/Bv9ARM.ch06.html Tony. -- f.anthony.n.finchhttp://dotat.at/ - I xn--zr8h pun

Blocking reverse lookup queries for private ips

2016-11-22 Thread Sachin Patil
Hello All, I want to forward reverse dns lookup queries for private ips to forwarders on my bind server. I have searched on internet and found I can have mapping to my private ips in ptr db records but I don't want this. I want to return nxdomain for any private ip reverse lookup. Can I do th