Limit queries per IP address.

João Martins jrmartiz at
Tue Mar 11 14:07:11 UTC 2008


I'm been using bind for several years and this is the first time I really
have a problem to solve. I've tried to get answers googling, and also
bind-list without any success, probably I didn't search with the right

I'm having several users doing aggressive recursive queries – around
44.000queries / min, the same of all the other users (about
18.000 users on my network). This affects bind performance and query reply
to other users sometimes fails.

Do I have any option that limit the number of queries for each client or
specific network? The idea is limiting a number of queries that a user (or
IP address) can do by second or even by minute.

I've a recursive limit queries on the global options "recursive-clients
1000;", but I think this penalties other users and not only the really abuse
users. I'm correct?

Anyone have other solution?




