DNSSEC signing common zone in views

2022-09-07 Thread Josef Vybíhal
Hello all, I am consolidating our old split DNS consisting of internal and external dedicated servers(VMs) into one primary server with views (there will be secondaries, but they are not important to the question). The old previous configuration is using inline-signing and auto-dnssec. I will be sw

Re: Zone transfer over VPN

2022-09-07 Thread Mark Andrews
Use tsig-keygen > On 7 Sep 2022, at 17:33, Michael De Roover wrote: > > On Wednesday, September 7, 2022 1:14:00 AM WEST John Thurston wrote: >> If you are dealing with two totally private networks, do you even need >> the ACL? >> >> But if you do need to limit access, then I suggest using TSIG

Re: Zone transfer over VPN

2022-09-07 Thread Michael De Roover
On Wednesday, September 7, 2022 1:14:00 AM WEST John Thurston wrote: > If you are dealing with two totally private networks, do you even need > the ACL? > > But if you do need to limit access, then I suggest using TSIG to > identify and authorize. This avoids the whole question of > source/destina