Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 8 Jul 1996 10:10:34 +0200 (GMT)
From:      Robin Lunn <robin@is.co.za>
To:        jrclark@netview.net (John Clark)
Cc:        questions@freebsd.org
Subject:   Re: stop "ls -d" in nslookup
Message-ID:  <199607080810.KAA02228@admin.is.co.za>
In-Reply-To: <2.2.32.19960708152638.0094b20c@netview.net> from "John Clark" at Jul 7, 96 03:27:23 pm

next in thread | previous in thread | raw e-mail | index | archive | help
John Clark wrote:
> Having looked at many different name servers (with nslookup), I see that
> some do not allow you to list their entire domain (ie. ls -d
> x.x.x.in-addr.arpa), although they seem to function properly, and give the
> scant information that a "set q=any" host query generates.  My question is
> how do I do this too?  I don't particularly want to leave my arpa table open
> for listing, but I do need arpa resolution.  Does anyone know the "trick" to
> stop my name server from being such a whore?  ;^)

Using bind 4.9.3 have a look at the bootfile option "xfernets".  To be
really secure, say that only the secondaries for your zones can do zone
transfers.

-- 
_ __                  | Only my ideas here unless I say otherwise...
' )  )     /          | (BeamJack@IRC)                 
 /--' ____/___o  __   | "Nondum amabam, et amare amabam...  quaerebam
/  \_(_) /_) (__/) )_ |  quid amarem, amans amare." - St Augustine



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199607080810.KAA02228>