Re: SERVFAIL takes precedence before RPZ policy action

2016-09-02 Thread Daniel Stirnimann
>> We maintain a block list with RPZ on our BIND resolvers. I noticed that >> the RPZ policy action does not apply for domain names which SERVFAIL >> (i.e. cannot be resolved by the resolver because of a timeout, lame >> delegation etc.). > > RPZ applies to responses not queries. > > You can over

Re: SERVFAIL takes precedence before RPZ policy action

2016-09-02 Thread Phil Mayers
On 02/09/16 15:22, Daniel Stirnimann wrote: Hi all We maintain a block list with RPZ on our BIND resolvers. I noticed that the RPZ policy action does not apply for domain names which SERVFAIL (i.e. cannot be resolved by the resolver because of a timeout, lame delegation etc.). RPZ applies to r

SERVFAIL takes precedence before RPZ policy action

2016-09-02 Thread Daniel Stirnimann
Hi all We maintain a block list with RPZ on our BIND resolvers. I noticed that the RPZ policy action does not apply for domain names which SERVFAIL (i.e. cannot be resolved by the resolver because of a timeout, lame delegation etc.). This happens on both BIND 9.11.0rc1 and 9.9.9-P2. Our default