Reject cached answers

Wael Shahin wael.shahin at
Thu Feb 1 10:18:40 UTC 2007

Hello List,
how can I prevent the replies that non-clients can get from my DNS servers
Since we have an authoritative name servers, we can't allow query for 
specific ACLs, and am wondering if a third party can gather statistics 
somehow out of this
assume I have the IP address range allowed for recursive and 
am allowing query for "any"
and a machine with the IP addresss tryed nslookup or pinging, then my server will reply withe the ip for if it is 
cached, it is not recursive but it still replies

am i getting this right ?

