diff options
author | Marco Platania <platania@research.att.com> | 2018-03-21 10:11:32 -0400 |
---|---|---|
committer | Marco Platania <platania@research.att.com> | 2018-03-21 16:58:22 +0000 |
commit | fe366e6d7ff18924cf33bd743e9674fa238f2b89 (patch) | |
tree | f54feae8c73e50a57f2cb7897147c2c018f0cd23 /vnfs/vLBMS/scripts/named.conf.options | |
parent | 2b40259f1cfe6a52360e70f696d8efaeeb16d8fa (diff) |
Add Heat templates and scripts for vLBMS
- Heat templates that install the vLBMS components
- Installation scripts that install and configure the VNF components
Change-Id: Ie1911a67b830d5543c96174fb915afd30d8daf0c
Issue-ID: INT-447
Signed-off-by: Marco Platania <platania@research.att.com>
Diffstat (limited to 'vnfs/vLBMS/scripts/named.conf.options')
-rw-r--r-- | vnfs/vLBMS/scripts/named.conf.options | 39 |
1 files changed, 39 insertions, 0 deletions
diff --git a/vnfs/vLBMS/scripts/named.conf.options b/vnfs/vLBMS/scripts/named.conf.options new file mode 100644 index 00000000..1daa65c3 --- /dev/null +++ b/vnfs/vLBMS/scripts/named.conf.options @@ -0,0 +1,39 @@ +acl "trusted" { + x.x.x.x; +}; +options { + directory "/var/cache/bind"; + + recursion no; # enables recursive queries + allow-recursion { trusted; }; # allows recursive queries from "trusted” clients i.e. LB only + listen-on { x.x.x.x; }; # ns1 IP address - listen on this address only + allow-transfer { none; }; # disable zone transfers by default + + forwarders { + 8.8.8.8; + 8.8.4.4; + }; + + + // If there is a firewall between you and nameservers you want + // to talk to, you may need to fix the firewall to allow multiple + // ports to talk. See http://www.kb.cert.org/vuls/id/800113 + + // If your ISP provided one or more IP addresses for stable + // nameservers, you probably want to use them as forwarders. + // Uncomment the following block, and insert the addresses replacing + // the all-0's placeholder. + + // forwarders { + // 0.0.0.0; + // }; + + //======================================================================== + // If BIND logs error messages about the root key being expired, + // you will need to update your keys. See https://www.isc.org/bind-keys + //======================================================================== + dnssec-validation auto; + + auth-nxdomain no; # conform to RFC1035 + listen-on-v6 { any; }; +}; |