query dropping vs. returning nxdomain

Jim Reid jim at rfc1035.com
Tue Mar 7 17:05:13 UTC 2006


On Mar 7, 2006, at 15:06, paul at vix.com wrote:

> i think that BIND, when a source address fails to match the allow- 
> query
> ACL, should have the option of "just drop", rather than sending DNS- 
> REFUSED.

<AOL Mode>Me too!</AOL Mode>

Could this proposed option also be available for allow-recursion?



More information about the bind-workers mailing list