Re: Getting RPZ statistics

2012-12-08 Thread John Hascall
> If you have a pointer to the technique you're using to > distinguish images and serve up replies, i'd be interested to see it. I'll be the first to admit it's not perfect, but even if we send the wrong content, it's better than what they would have gotten! :) First we just look at th

Re: Getting RPZ statistics

2012-12-08 Thread Phil Mayers
We do much the same. If you have a pointer to the technique you're using to distinguish images and serve up replies, i'd be interested to see it. John Hascall wrote: > >We point our DNS-RPZ records at a server ("here-be-dragons") >that records connections at that point. Also the webserver >li

Re: Getting RPZ statistics

2012-12-07 Thread John Hascall
We point our DNS-RPZ records at a server ("here-be-dragons") that records connections at that point. Also the webserver listening there sends back either and image or javascript+html which explains to the user the reason they are not seeing the webpage they expect. The web server gives us a conv

Re: Getting RPZ statistics

2012-12-07 Thread Vernon Schryver
> From: "Howard, Christopher Bryan" > I recently (as of 2 days ago) enabled RPZ on all of my name servers. I cur= > rently use "rndc stats", perl, and SNMP to make certain global stats availa= > ble to our network monitoring system to make charts (number of queries acro= > ss all views and such)

Getting RPZ statistics

2012-12-07 Thread Howard, Christopher Bryan
I recently (as of 2 days ago) enabled RPZ on all of my name servers. I currently use "rndc stats", perl, and SNMP to make certain global stats available to our network monitoring system to make charts (number of queries across all views and such). I'd like to do the same for just the RPZ zone