RE: Name resolution failure on a caching server -- many '; pending-answer' records in the cache

2016-01-27 Thread Darcy Kevin (FCA)
NXDOMAIN is not a "failure" response. Are you *sure* you're getting NXDOMAIN? If you're using nslookup to test, be aware that it will do suffix searching by default, so if the original query, e.g. www.bbc.co.uk fails, it'll quietly (unless debug-mode is in effect) start appending suffixes. Look

RPZ PASSTHRU logging

2016-01-27 Thread Paul Seward
Hi all, I'm experimenting with RPZ on a reasonably high volume resolver. I've got the following response-policy block defined: response-policy { zone "local-whitelist.rpz" policy PASSTHRU; zone "local-blacklist.rpz" policy CNAME rpz-target.bris.ac.uk.; }; This is working fine. Domains