mirror of
https://github.com/isc-projects/bind9.git
synced 2026-04-28 17:46:40 -04:00
3620. [func] Added "rpz-client-ip" policy triggers, enabling RPZ responses to be configured on the basis of the client IP address; this can be used, for example, to blacklist misbehaving recursive or stub resolvers. [RT #33605] 3619. [bug] Fixed a bug in RPZ with "recursive-only no;" [RT #33776]
63 lines
1.8 KiB
Text
63 lines
1.8 KiB
Text
; Copyright (C) 2011-2013 Internet Systems Consortium, Inc. ("ISC")
|
|
;
|
|
; Permission to use, copy, modify, and/or distribute this software for any
|
|
; purpose with or without fee is hereby granted, provided that the above
|
|
; copyright notice and this permission notice appear in all copies.
|
|
;
|
|
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
|
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
|
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
|
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
|
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
|
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
|
; PERFORMANCE OF THIS SOFTWARE.
|
|
|
|
|
|
|
|
; Use comment lines instead of blank lines to combine update requests into
|
|
; single requests
|
|
; Separate update requests for distinct TLDs with blank lines or 'send'
|
|
; End the file with a blank line or 'send'
|
|
|
|
; the policies or replacements specified in ns3/named.conf override these
|
|
|
|
server 10.53.0.3 5300
|
|
|
|
; 1
|
|
update add a3-1.tld2.bl-given. 300 A 127.0.0.1
|
|
send
|
|
; 2
|
|
update add a3-2.tld2.bl-passthru. 300 A 127.0.0.2
|
|
send
|
|
; 3
|
|
update add a3-3.tld2.bl-no-op. 300 A 127.0.0.3
|
|
send
|
|
; 4
|
|
update add a3-4.tld2.bl-disabled. 300 A 127.0.0.4
|
|
send
|
|
; 5 - 7
|
|
update add a3-5.tld2.bl-nodata. 300 A 127.0.0.5
|
|
send
|
|
; 11
|
|
update add a3-6.tld2.bl-nxdomain. 300 A 127.0.0.11
|
|
send
|
|
; 12
|
|
update add a3-7.tld2.bl-cname. 300 A 127.0.0.12
|
|
send
|
|
; 13
|
|
update add a3-8.tld2.bl-wildcname. 300 A 127.0.0.13
|
|
; 14
|
|
update add *.sub9.tld2.bl-wildcname. 300 A 127.0.1.14
|
|
send
|
|
; 15
|
|
update add a3-15.tld2.bl-garden. 300 A 127.0.0.15
|
|
send
|
|
; 16
|
|
update add a3-16.tld2.bl. 300 A 127.0.0.16
|
|
send
|
|
; 18
|
|
update add a3-18.tld2.bl-drop. 300 A 127.0.0.18
|
|
send
|
|
; 19
|
|
update add a3-19.tld2.bl-tcp-only. 300 A 127.0.0.19
|
|
send
|