BIND on ipv6-only server. SERVFAIL problem

2019-12-06 Thread Andrey Geyn
Hello, I have installed BIND on IPv6-only server with firewalled access to the internet (assume that access is allowed only to port 53 to forwarder). It works good, but sometimes BIND receive SERVFAIL response from forwarder (and we can see "remote server broken: returned  SERVFAIL" in logs). But f

Re: Internal CNAME in RPZ

2019-10-24 Thread Andrey Geyn
Thank you, Bob. Unfortunately, records are generated by my users, not by me, so I can't change them as I want. Thanks again for your time and detailed explanation. Andrey. 24.10.2019, 19:53, "Bob Harold" : > On Thu, Oct 24, 2019 at 9:20 AM Andrey Geyn wrote: >>

Re: Internal CNAME in RPZ

2019-10-24 Thread Andrey Geyn
this behaivor? Andrey 24.10.2019, 18:06, "Bob Harold" : On Wed, Oct 23, 2019 at 10:34 AM Andrey Geyn <andg...@yandex-team.ru> wrote:Hello, I would like to set up RPZ with CNAME and A. There are two options: 1.cname.domain.com        CNAME   test.domain.com    (without trailing

Re: Internal CNAME in RPZ

2019-10-23 Thread Andrey Geyn
what I would expect to see from an > RPZ-mediated query, but rather what I would expect to see if querying a > zone, such as the RPZ itself, directly. So I am not sure I understand your > question. > > To the broader ISC community: however, I'm confused by the response I'm

Internal CNAME in RPZ

2019-10-23 Thread Andrey Geyn
Hello, I would like to set up RPZ with CNAME and A. There are two options: 1.cname.domain.com        CNAME   test.domain.com    (without trailing dot)test.domain.com         A       10.10.10.10 In this case I receive # dig cname.domain.com @127.0.0.1...cname.domain.com.       5       IN      CNAME