Re: [External] Re: Request assistance configuring RPZ

2019-05-29 Thread Grant Taylor via bind-users
On 5/29/19 3:15 PM, Jon wrote: Hi Grant, Hi, I don't usually wade in on these but I also believe RPZ would be the simplest way to achieve this. I tend to agree. DNSSEC can complicate this a bit (requiring additional settings). In order to keep the same zone working with 10. Addressing for

Re: [External] Re: Request assistance configuring RPZ

2019-05-29 Thread Jon
Hi Grant, I don't usually wade in on these but I also believe RPZ would be the simplest way to achieve this. You're close I think. Using Carl's information and what you've done there, add the following. In order to keep the same zone working with 10. Addressing for all other (not in bubble) clie

Re: [External] Re: Request assistance configuring RPZ

2019-05-29 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2019-05-29 at 09:05 -0400, David Bank wrote: > Re-reading the ARM, it seemed to me that I needed to add a After adding the zone and the response-policy statement to named.conf, I presume you did: rndc reconfig To test that you can:

Re: [External] Re: Request assistance configuring RPZ

2019-05-29 Thread David Bank
On Tue, 28 May 2019, Carl Byington via bind-users wrote: Hi, Carl - thanks for replying. On zurg, add a new dns zone rpz.ncdot.gov Your suggestion didn't work for me. To test your suggestion, I had to add a "forwarders" statement to get zurg to query buzz/woody; prior to testing,

Re: [External] Re: Request assistance configuring RPZ

2019-05-28 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2019-05-28 at 13:13 -0400, David Bank wrote: > Perhaps I'm missing something, but I don't see how to make zurg reply > with 192.168/16 IPs for andy and sid, but correctly resolve the rest > of *.internal.local On zurg, add a new dns zone rpz

Re: [External] Re: Request assistance configuring RPZ

2019-05-28 Thread Grant Taylor via bind-users
On 5/28/19 11:13 AM, David Bank wrote: Hello, Grant! Thanks for replying. Hi. You're welcome.     No - the bubble is its own world for the most part. No reason for general 10/8 inhabitants to try to talk to 192.168/16 - the very, very few hosts that need to talk in 192.168/16 already have

Re: [External] Re: Request assistance configuring RPZ

2019-05-28 Thread Sten Carlsen
To me this looks like it could be done with a bit of programming. If the addresses of the two hosts needed in 192.168.x.x don't change too often, a cron job could read those addresses and set them in zurg as dynamic entries using nsupdate. The time for cron would be smaller than the TTL of the RRs

Re: [External] Re: Request assistance configuring RPZ

2019-05-28 Thread David Bank
On Tue, 28 May 2019, Grant Taylor via bind-users wrote: Hello, Grant! Thanks for replying. On 5/28/19 10:16 AM, David Bank wrote: To recap what I'm attempting to create: a host in the 10. network knows to ask buzz or woody for DNS resolution, and if such a host wants to resolve andy.internal.l