multiple `zone' clauses for a single domain?

Jan-Piet Mens jpmens.dns at
Sat Nov 26 07:04:34 UTC 2011

> The documentation for `match-clients' isn't comprehensive enough... Can
> I add all host from, for example 172.16/16 except a single host? Does:
> match-clients {;!; }

BIND checks the ACL in the order you specify. In your example, will be allowed by the first rule. Change the order:

        match-clients {

This disallows first, which will work as you expect it to.


