Re: Actual BIND error - Patching OpenBSD 4.3 named ?

Previous thread: Re: ntpd.conf with nmea by Stuart Henderson on Wednesday, July 9, 2008 - 8:29 am. (2 messages)

Next thread: Vulnerability Note VU#800113 - Multiple DNS implementations vulnerable to cache poisoning by Zamri Besar on Wednesday, July 9, 2008 - 10:45 am. (8 messages)
To: <misc@...>
Date: Wednesday, July 9, 2008 - 9:17 am

thanks to those who pointed out (self) includes 127.0.0.1, so you
don't want to use -> (self), rather use -> (egress).

e.g. "nat on egress proto udp from (self) to any port 53 -> (egress)",

if you have a larger address space available you can use more
of it, e.g. you can use "{192.0.192.0/24} random" on a firewall in
front of name servers.

Previous thread: Re: ntpd.conf with nmea by Stuart Henderson on Wednesday, July 9, 2008 - 8:29 am. (2 messages)

Next thread: Vulnerability Note VU#800113 - Multiple DNS implementations vulnerable to cache poisoning by Zamri Besar on Wednesday, July 9, 2008 - 10:45 am. (8 messages)