ECS subnet

Rainer Duffner rainer at ultra-secure.de
Fri Feb 14 16:35:56 UTC 2025


Hi,

I have a setup where I have a BIND resolver behind an unbound resolver.

The reason is that when I originally set this up, there was no way to integrate an RPZ feed into unbound.

It seems possible now but I haven’t really wanted to try it out….


Of course, this leads to the situation where the actual RPZ-log of the BIND server doesn’t have any other IPs than that of the unbound resolver above it.

I thought that with the "send-client-subnet: 127.0.0.1“ configuration in unbound, I could „send“ at least the client subnet to BIND.

But is it possible to show this in the logs?




Rainer


More information about the bind-users mailing list