summaryrefslogtreecommitdiffstats
path: root/vnfs/vLBMS/scripts/named.conf.options
diff options
context:
space:
mode:
authorMarco Platania <platania@research.att.com>2018-03-21 10:11:32 -0400
committerMarco Platania <platania@research.att.com>2018-03-21 16:58:22 +0000
commitfe366e6d7ff18924cf33bd743e9674fa238f2b89 (patch)
treef54feae8c73e50a57f2cb7897147c2c018f0cd23 /vnfs/vLBMS/scripts/named.conf.options
parent2b40259f1cfe6a52360e70f696d8efaeeb16d8fa (diff)
Add Heat templates and scripts for vLBMS
- Heat templates that install the vLBMS components - Installation scripts that install and configure the VNF components Change-Id: Ie1911a67b830d5543c96174fb915afd30d8daf0c Issue-ID: INT-447 Signed-off-by: Marco Platania <platania@research.att.com>
Diffstat (limited to 'vnfs/vLBMS/scripts/named.conf.options')
-rw-r--r--vnfs/vLBMS/scripts/named.conf.options39
1 files changed, 39 insertions, 0 deletions
diff --git a/vnfs/vLBMS/scripts/named.conf.options b/vnfs/vLBMS/scripts/named.conf.options
new file mode 100644
index 00000000..1daa65c3
--- /dev/null
+++ b/vnfs/vLBMS/scripts/named.conf.options
@@ -0,0 +1,39 @@
+acl "trusted" {
+ x.x.x.x;
+};
+options {
+ directory "/var/cache/bind";
+
+ recursion no; # enables recursive queries
+ allow-recursion { trusted; }; # allows recursive queries from "trusted” clients i.e. LB only
+ listen-on { x.x.x.x; }; # ns1 IP address - listen on this address only
+ allow-transfer { none; }; # disable zone transfers by default
+
+ forwarders {
+ 8.8.8.8;
+ 8.8.4.4;
+ };
+
+
+ // If there is a firewall between you and nameservers you want
+ // to talk to, you may need to fix the firewall to allow multiple
+ // ports to talk. See http://www.kb.cert.org/vuls/id/800113
+
+ // If your ISP provided one or more IP addresses for stable
+ // nameservers, you probably want to use them as forwarders.
+ // Uncomment the following block, and insert the addresses replacing
+ // the all-0's placeholder.
+
+ // forwarders {
+ // 0.0.0.0;
+ // };
+
+ //========================================================================
+ // If BIND logs error messages about the root key being expired,
+ // you will need to update your keys. See https://www.isc.org/bind-keys
+ //========================================================================
+ dnssec-validation auto;
+
+ auth-nxdomain no; # conform to RFC1035
+ listen-on-v6 { any; };
+};