Disallow recursive DNS queries 97/2997/1
authorMarco Platania <platania@research.att.com>
Tue, 4 Apr 2017 16:35:22 +0000 (12:35 -0400)
committerMarco Platania <platania@research.att.com>
Tue, 4 Apr 2017 16:35:22 +0000 (12:35 -0400)
Change-Id: Iec14e531448e30ef19b3efb6301100c462860558
Signed-off-by: Marco Platania <platania@research.att.com>
boot/bind_options
boot/bind_zones

index d65cc32..0bb6769 100644 (file)
@@ -4,8 +4,8 @@ acl "trusted" {
 options {
         directory "/var/cache/bind";
 
-        recursion yes;                 # enables recursive queries
-        allow-recursion { netmask; };  # allows recursive queries from "trusted” clients i.e. LB only
+        recursion no;                 # enables recursive queries
+        //allow-recursion { netmask; };  # allows recursive queries from "trusted” clients i.e. LB only
         listen-on { dns_ip_addr; };   # ns1 IP address - listen on this address only
         allow-transfer { none; };      # disable zone transfers by default
 
index 1c0b27e..73b2158 100644 (file)
@@ -64,7 +64,7 @@ vm1.portal.simpledemo.openecomp.org.           IN      A       portal_ip_addr
 c1.vm1.portal.simpledemo.openecomp.org.        IN      A       portal_ip_addr
 c2.vm1.portal.simpledemo.openecomp.org.        IN      A       portal_ip_addr
 
-vm1.aaf.simpledemo.openecomp.org.      IN      A       aaf_ip_addr
+;vm1.aaf.simpledemo.openecomp.org.     IN      A       aaf_ip_addr
 
 vm1.mr.simpledemo.openecomp.org.       IN      A       mr_ip_addr