bind 8.2.2-P5 and Query Class = 255

Serge Andrey Serge.Andrey at unifr.ch
Mon Jan 17 16:29:49 UTC 2000


Hi,

I am running BIND 8.2.2-P5 with the configuration found in the following
document from AUSCERT to protect against Dos attacks using DNS.

  ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos


With this configuration, sometimes BIND generate log messages :

  unapproved query from [a.b.c.d].4900 for "1.1.21.134.in-addr.arpa"


This message is generated only when 'Query Class = 255'.
Very few queries arrive with this 'Query Class' but they are refused.

Any idea ?


Thanks
Serge



More information about the bind-users mailing list