From 2b556b22a1c446670a9e7f7030b24da136dbf45b Mon Sep 17 00:00:00 2001 From: platania Date: Tue, 14 Mar 2017 14:14:15 -0400 Subject: disable unexpected updates in robot VM Change-Id: I24280be8f3bdc5237554b8e46fe9a7909a97795c Signed-off-by: platania --- boot/bind_options | 39 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) create mode 100644 boot/bind_options (limited to 'boot/bind_options') diff --git a/boot/bind_options b/boot/bind_options new file mode 100644 index 00000000..d65cc323 --- /dev/null +++ b/boot/bind_options @@ -0,0 +1,39 @@ +acl "trusted" { + #x.x.x.x; +}; +options { + directory "/var/cache/bind"; + + recursion yes; # enables recursive queries + allow-recursion { netmask; }; # allows recursive queries from "trusted” clients i.e. LB only + listen-on { dns_ip_addr; }; # ns1 IP address - listen on this address only + allow-transfer { none; }; # disable zone transfers by default + + forwarders { + 8.8.8.8; + 8.8.4.4; + }; + + // If there is a firewall between you and nameservers you want + // to talk to, you may need to fix the firewall to allow multiple + // ports to talk. See http://www.kb.cert.org/vuls/id/800113 + + // If your ISP provided one or more IP addresses for stable + // nameservers, you probably want to use them as forwarders. + // Uncomment the following block, and insert the addresses replacing + // the all-0's placeholder. + + // forwarders { + // 0.0.0.0; + // }; + + //======================================================================== + // If BIND logs error messages about the root key being expired, + // you will need to update your keys. See https://www.isc.org/bind-keys + //======================================================================== + dnssec-validation auto; + + auth-nxdomain no; # conform to RFC1035 + listen-on-v6 { any; }; +}; + -- cgit 1.2.3-korg