Re: RPZ and DNS traffic on the server

2019-02-12 Thread Alex K
Hi Daniel, Thank you very much! It was exactly what I was looking for. On Tue, Feb 12, 2019 at 4:03 PM Daniel Stirnimann < daniel.stirnim...@switch.ch> wrote: > > Hello Alex, > > > Is this expected behaviour? Is there any way to make the server avoid > > proceeding with the resolution, when the

Re: RPZ and DNS traffic on the server

2019-02-12 Thread Daniel Stirnimann
Hello Alex, > Is this expected behaviour? Is there any way to make the server avoid > proceeding with the resolution, when the initial client requests is > blocked? Yes, this is expected behavior. You need "qname-wait-recurse no" to change the behavior: response-policy { zone "rpz-whitelist-

RPZ and DNS traffic on the server

2019-02-12 Thread Alex K
Hi all, I have a RPZ setup to whitelist several domains. The issue I am facing is that, even though domains are blocked, the cashing DNS server still proceeds to resolve the domain. The bahavior that I was hoping to see is the server to not bother resolving the domain if the RPZ policy replies wit