Skip to Content.
Sympa Menu

dns-operations - Re: [opennic-dns-operations] Should I act on bad notify attempts?

dns-operations AT lists.opennicproject.org

Subject: Dns-operations mailing list

List archive

Re: [opennic-dns-operations] Should I act on bad notify attempts?


Chronological Thread 
  • From: Brian Koontz <brian AT opennicproject.org>
  • To: dns-operations AT lists.opennicproject.org
  • Subject: Re: [opennic-dns-operations] Should I act on bad notify attempts?
  • Date: Sat, 9 Feb 2013 12:41:01 -0600

On Sat, Feb 09, 2013 at 12:09:20PM -0500, Steve Snyder wrote:
>
> On 02/09/2013 11:18 AM, Brian Koontz wrote:
> >On Sat, Feb 09, 2013 at 08:56:52AM -0500, Steve Snyder wrote:
> >>There are a handful of non-Master DNS servers that constantly try to
> >>notify my server. Should I act on this (block via iptables, etc.)
> >>or just accept that there will always be misconfigured servers
> >>somewhere and ignore them?
> >...
> >> 2079 2001:470:1f10:c6::20
> >...
> >
> >This is interesting, because this one is mine, and each zone I serve
> >explictly specifies "notify no." Which zones exactly are you
> >receiving notifies for?
> >
> > --Brian
> >
>
> 09-Feb-2013 16:42:06.865 notify: client 2001:470:1f10:c6::20#15520:
> received notify for zone 'dns.opennic.glue'
> 09-Feb-2013 16:42:06.865 general: zone dns.opennic.glue/IN: refused
> notify from non-master: 2001:470:1f10:c6::20#15520

Relevant snip from named.conf:

zone "dns.opennic.glue" IN {
type slave;
file "opennic/slave/dns.opennic.glue.zone";
masters { 75.127.96.89; };
allow-transfer { any; };
notify no;
};

Don't know what to say...the do-not-notify instruction is right there.

--Brian

--
OpenNIC (the sequel) co-founder and wikimaster
IRC: Freenode.net channel #opennic



Archive powered by MHonArc 2.6.19.

Top of Page