Re: Adding subnet to firewalld drop zone

2018-08-12 Thread Dirk Gottschalk via users
Hi. Am Donnerstag, den 09.08.2018, 00:20 +0100 schrieb Danny Horne via users: > On 08/08/18 23:27, Dirk Gottschalk via users wrote: > > You have to find out whi issues the query. I would disable > > recursion at > > all except for the internal network. > > > > Find out who queries this domains

Re: Adding subnet to firewalld drop zone

2018-08-08 Thread Danny Horne via users
On 08/08/18 23:27, Dirk Gottschalk via users wrote: > You have to find out whi issues the query. I would disable recursion at > all except for the internal network. > > Find out who queries this domains and answer witth NXDOMAIN, disabling > recursion would do thos. Blocking DNS queries if you are

Re: Adding subnet to firewalld drop zone

2018-08-08 Thread Danny Horne via users
On 08/08/18 23:27, Dirk Gottschalk via users wrote: > No, this is the queried DNS. It is the authoritative NS for the Domain > barracudacentral.org. > > Seems to be some kind of reverse entry which does not resolve > correctly. The Source for the query is not mentioned. The authotitative > can not

Re: Adding subnet to firewalld drop zone

2018-08-08 Thread Dirk Gottschalk via users
Hi. Am Mittwoch, den 08.08.2018, 22:27 +0100 schrieb Danny Horne via users: > Hi all, > > I've been trying to add a subnet to my firewalld drop zone because > queries from this subnet have been filling up my named logs and I've > had enough!! > > Based on research these are some assumptions

Adding subnet to firewalld drop zone

2018-08-08 Thread Danny Horne via users
Hi all, I've been trying to add a subnet to my firewalld drop zone because queries from this subnet have been filling up my named logs and I've had enough!! Based on research these are some assumptions I've made - Adding a subnet to a zone makes it an active zone Zones with subnets take