diff options
author | Marco Platania <platania@research.att.com> | 2017-04-04 12:35:22 -0400 |
---|---|---|
committer | Marco Platania <platania@research.att.com> | 2017-04-04 12:35:22 -0400 |
commit | ab4f2ac28193bc7e3994f57043e65c3a145f031b (patch) | |
tree | efde1fcc87d87e07fb5db6c16c417b2704aeed47 | |
parent | 05d20012109a28272701446b64559da2efcbd743 (diff) |
Disallow recursive DNS queries
Change-Id: Iec14e531448e30ef19b3efb6301100c462860558
Signed-off-by: Marco Platania <platania@research.att.com>
-rw-r--r-- | boot/bind_options | 4 | ||||
-rw-r--r-- | boot/bind_zones | 2 |
2 files changed, 3 insertions, 3 deletions
diff --git a/boot/bind_options b/boot/bind_options index d65cc323..0bb67697 100644 --- a/boot/bind_options +++ b/boot/bind_options @@ -4,8 +4,8 @@ acl "trusted" { options { directory "/var/cache/bind"; - recursion yes; # enables recursive queries - allow-recursion { netmask; }; # allows recursive queries from "trusted” clients i.e. LB only + recursion no; # enables recursive queries + //allow-recursion { netmask; }; # allows recursive queries from "trusted” clients i.e. LB only listen-on { dns_ip_addr; }; # ns1 IP address - listen on this address only allow-transfer { none; }; # disable zone transfers by default diff --git a/boot/bind_zones b/boot/bind_zones index 1c0b27e7..73b21583 100644 --- a/boot/bind_zones +++ b/boot/bind_zones @@ -64,7 +64,7 @@ vm1.portal.simpledemo.openecomp.org. IN A portal_ip_addr c1.vm1.portal.simpledemo.openecomp.org. IN A portal_ip_addr c2.vm1.portal.simpledemo.openecomp.org. IN A portal_ip_addr -vm1.aaf.simpledemo.openecomp.org. IN A aaf_ip_addr +;vm1.aaf.simpledemo.openecomp.org. IN A aaf_ip_addr vm1.mr.simpledemo.openecomp.org. IN A mr_ip_addr |