It comes to my attention that when an unresolvable query occurs, it gets forwarded to the authoritative zone regardless of anything I can set in named.conf. Closest I can come is qname-wait-recurse which has the opposite effect sort of, namely waiting for recursion to complete. If I have something in an RPZ, I want it to accept that; period, full stop, no outwardly visible effects.
Ironically the text surrounding this option in the ARM is to the effect that "... not resolving the requested name can leak the fact that response policy rewriting is in use..." and leaking the fact that it is in use by not leaking the query in the first place is what I'm trying to achieve: how do I disable the (useless) resolution directed at upstream servers?
Here is a use case:
In this case:
Let's stop the leaks.
--
Fred Morris
Четверг, 3 сентября 2020, 19:04 +03:00 от Fred Morris <m3...@m3047.net>:
_______________________________________________
DNSfirewalls mailing list
DNSfir...@lists.redbarn.org
http://lists.redbarn.org/mailman/listinfo/dnsfirewalls