Vulnerable DNS servers, RFC

Kevin Darcy kcd at daimlerchrysler.com
Tue Oct 25 21:30:25 UTC 2005


Brad Knowles wrote:

>At 4:04 PM +0000 2005-10-25, Thomas Schulz wrote:
>
>  
>
>> Can't you do this with views?  Could you make one view authoritative-only
>> and another view recursive?  I know that you can give out different
>> authoritative data from different views and I thought that I had read
>> somewhere that views could also differ in whether recursion was allowed
>> or not.
>>    
>>
>
>	The problem is that views will still use the same shared database.
>
>	Moreover, you can do views based on the incoming source IP 
>address of the query, but not on the IP address of the interface on 
>which the query is coming in on.  ACLs look at the IP address of the 
>query, not the IP address of the interface.
>
Actually, "match-destinations" has been around since around 9.2.2 or so...

- Kevin





More information about the bind-users mailing list