|
<- Previous Message | Next Message -> Thread Index [isp-dns] RE: special DNS server
spoofing authority for the handful of domains (if enough records can be harvested from the auth servers) is the simplest and most efficient. no firewall manips at all. The problem is your server answering with stale records. A thorough solution would have a script that updated the spoofed zones with current records from auth servers.btw, if you can use allow-query rather than allow-recursion, you avoid BIND wasting its time responding to denied recursion with referrals. Denied query returns a minimal packet (2 sections) with a header RCODE of REFUSED. Len _____________________________________________________________________ http://MenAndMice.com/DNS-training : Wash DC; Atlanta; SFO; Denver; NYC http://IMGate.MEIway.com : free anti-spam gateway, runs on 1000's of sites To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016 Please include the email address which you have been contacted with.
Thread Index |