allow-query and views

2013-02-21 Thread Robert Moskowitz
I am reading: https://www.isc.org/software/bind/faq and 'What has changed in the behavior of "allow-recursion" and "allow-query-cache" '. I am struggling here trying to match up the various access control features, particularly when we are suppose to have different views for different clients

Re: allow-query and views

2013-02-21 Thread Matus UHLAR - fantomas
On 21.02.13 08:59, Robert Moskowitz wrote: I am reading: https://www.isc.org/software/bind/faq and 'What has changed in the behavior of "allow-recursion" and "allow-query-cache" '. I am struggling here trying to match up the various access control features, particularly when we are suppose t

Re: allow-query and views

2013-02-21 Thread Robert Moskowitz
On 02/21/2013 10:40 AM, Matus UHLAR - fantomas wrote: On 21.02.13 08:59, Robert Moskowitz wrote: I am reading: https://www.isc.org/software/bind/faq and 'What has changed in the behavior of "allow-recursion" and "allow-query-cache" '. I am struggling here trying to match up the various acces

Re: allow-query and views

2013-02-21 Thread Vernon Schryver
> > correct, no external hosts should query your cache. > > > OK. There is no substitute for testing assumptions, mailing list assurances, understandings of documentation, etc. Test from outside your network to see that your DNS servers don't answer requests they shouldn't and answer those they s

Re: allow-query and views

2013-02-21 Thread Matus UHLAR - fantomas
On 21.02.13 08:59, Robert Moskowitz wrote: I am reading: https://www.isc.org/software/bind/faq and 'What has changed in the behavior of "allow-recursion" and "allow-query-cache" '. I am struggling here trying to match up the various access control features, particularly when we are suppose t

Re: allow-query and views

2013-02-21 Thread Robert Moskowitz
On 02/21/2013 12:10 PM, Matus UHLAR - fantomas wrote: On 21.02.13 08:59, Robert Moskowitz wrote: I am reading: https://www.isc.org/software/bind/faq and 'What has changed in the behavior of "allow-recursion" and "allow-query-cache" '. I am struggling here trying to match up the various acce

Re: allow-query and views

2013-02-21 Thread Robert Moskowitz
On 02/21/2013 11:50 AM, Vernon Schryver wrote: correct, no external hosts should query your cache. OK. There is no substitute for testing assumptions, mailing list assurances, understandings of documentation, etc. Test from outside your network to see that your DNS servers don't answer reque

Re: allow-query and views

2013-02-21 Thread Mike Hoskins (michoski)
-Original Message- From: Robert Moskowitz Date: Thursday, February 21, 2013 12:53 PM To: Vernon Schryver Cc: "bind-users@lists.isc.org" Subject: Re: allow-query and views >Whow... This is news. A hidden view? Where is this documented. I >have no restrictions in my

Re: allow-query and views

2013-02-21 Thread Robert Moskowitz
On 02/21/2013 12:58 PM, Mike Hoskins (michoski) wrote: -Original Message- From: Robert Moskowitz Date: Thursday, February 21, 2013 12:53 PM To: Vernon Schryver Cc: "bind-users@lists.isc.org" Subject: Re: allow-query and views Whow... This is news. A hidden view? Whe

Re: allow-query and views

2013-02-21 Thread Matus UHLAR - fantomas
On 21.02.13 12:45, Robert Moskowitz wrote: Fact: No clients could access DNS from my server, both internal and external (I have hotspot on my cellphone, so I can attach a client to it to get external testing) UNTIL I added the allow-query option. Once added things started working right. W

Re: allow-query and views

2013-02-21 Thread Vernon Schryver
> From: Robert Moskowitz > Whow... This is news. A hidden view? Where is this documented. The ARM says in part: Built-in server information zones The server provides some helpful diagnostic information through a number of built-in zones under the pseudo-top-level-domain bind i

Re: allow-query and views

2013-02-21 Thread Robert Moskowitz
On 02/21/2013 01:54 PM, Matus UHLAR - fantomas wrote: On 21.02.13 12:45, Robert Moskowitz wrote: Fact: No clients could access DNS from my server, both internal and external (I have hotspot on my cellphone, so I can attach a client to it to get external testing) UNTIL I added the allow-quer

Re: allow-query and views

2013-02-21 Thread Vernon Schryver
> The ARM says in part: > > Built-in server information zones > The server provides some helpful diagnostic information through a > number of built-in zones under the pseudo-top-level-domain bind > in the CHAOS class. These zones are part of a built-in view (see > the section call

Re: allow-query and views

2013-02-21 Thread Robert Moskowitz
On 02/21/2013 02:04 PM, Vernon Schryver wrote: From: Robert Moskowitz Whow... This is news. A hidden view? Where is this documented. The ARM says in part: Built-in server information zones The server provides some helpful diagnostic information through a number of built-in zon

Re: allow-query and views

2013-02-21 Thread Robert Moskowitz
On 02/21/2013 02:16 PM, Vernon Schryver wrote: The ARM says in part: Built-in server information zones The server provides some helpful diagnostic information through a number of built-in zones under the pseudo-top-level-domain bind in the CHAOS class. These zones are part of