Stopping name server abuse

Barry Margolin barmar at
Mon Jun 25 15:34:19 UTC 2018

In article <mailman.79.1529899821.803.bind-users at>,
 "Browne, Stuart" <Stuart.Browne at> wrote:

> If you're filtering on an upstream device that can do that level of analysis 
> without hurting your network, then maybe, but once again, you're 
> double-processing every legitimate query; you're only moving the cost to a 
> different device.

An upstream firewall might already be parsing it, so telling it not to 
pass some of them through could be relatively cheap.

Barry Margolin
Arlington, MA

