rpz using a forward zone

Mike Woods cceaood at ucl.ac.uk
Wed Jun 5 10:04:17 UTC 2019


Hi Guys, hopefully a pretty straightforward question for my first post 
to the list.

We're trying to mitigate an issue with the spamhaus dbl list 
interrupting our internal dns service (and yes, I'm aware that this is a 
known issue and fixes exist in later builds but there are issues for us 
updating bind itself right now), to that end I've setup rbldnsd to serve 
a parsed copy of the spamhaus zonefile (using dig to pull down a copy 
mitigate any issues) and this is working as expected however if I 
configure the response policy in bind to use the resulting forward zone 
for this it fails to start and it's not clear from the documentation if 
this needs to be a physical zone file or not.

So, the long and short of things, is it actually possible to point the 
response policy at a forward zone or am I pissing my time up the wall ?

Mike Woods


More information about the bind-users mailing list