Re: BIND RPZ is not blocking A record

2024-11-18 Thread Blason R
That is what I exactly did and noticed that packets are received on bind and bind is directly forwarding. See my first email that has packet captures On Sun, Nov 17, 2024, 18:17 Lee wrote: > On Sun, Nov 17, 2024 at 1:28 AM Blason R wrote: > > > > Nah even that didn't work. > > > > If I directly

Re: BIND RPZ is not blocking A record

2024-11-17 Thread Lee
On Sun, Nov 17, 2024 at 1:28 AM Blason R wrote: > > Nah even that didn't work. > > If I directly query to bind it blocks or wall garden the request but if I > send it through windows AD or any other server bind just forwards the request > to forwarders. How do you _know_ windows AD or any other

Re: BIND RPZ is not blocking A record

2024-11-17 Thread Blason R
Agree but response for app.hubspot.com.is getting modified and i see issue with only this domain. On Sun, Nov 17, 2024, 12:01 Mark Andrews wrote: > RPZ stands for RESPONSE POLICY ZONE. It does NOT block queries. It > modifies replies. > -- > Mark Andrews > > On 17 Nov 2024, at 17:28, Blason R w

Re: BIND RPZ is not blocking A record

2024-11-16 Thread Blason R
Nah even that didn't work. If I directly query to bind it blocks or wall garden the request but if I send it through windows AD or any other server bind just forwards the request to forwarders. On Sat, Nov 16, 2024, 23:55 Lee wrote: > Hi > > On Fri, Nov 15, 2024 at 10:24 PM Blason R wrote: > >

Re: BIND RPZ is not blocking A record

2024-11-16 Thread Mark Andrews
RPZ stands for RESPONSE POLICY ZONE. It does NOT block queries. It modifies replies. -- Mark AndrewsOn 17 Nov 2024, at 17:28, Blason R wrote:Nah even that didn't work.If I directly query to bind it blocks or wall garden the request but if I send it through windows AD or any other server bind just

Re: BIND RPZ is not blocking A record

2024-11-16 Thread Lee
Hi On Fri, Nov 15, 2024 at 10:24 PM Blason R wrote: > > Where is that exactly to be added? I added in response-policy > statement then I tired adding in options stanza but rndc fails > everytime. > <.. snip ..> > > > > response-policy { > > > > zone "custom.block"; > > > > ... > > > > .. > > >

Re: BIND RPZ is not blocking A record

2024-11-15 Thread Benny Pedersen
Blason R skrev den 2024-11-16 04:24: Where is that exactly to be added? I added in response-policy statement then I tired adding in options stanza but rndc fails everytime. try this response-policy { zone "rpz.localhost"; } break-dnssec yes qname-wait-recurse no recursi

Re: BIND RPZ is not blocking A record

2024-11-15 Thread Blason R
Where is that exactly to be added? I added in response-policy statement then I tired adding in options stanza but rndc fails everytime. On Fri, Nov 15, 2024 at 6:35 PM Blason R wrote: > > Hmmm - Ok let me try doing that. Thanks for letting me know > > On Fri, Nov 15, 2024 at 3:43 PM Lee wrote:

Re: BIND RPZ is not blocking A record

2024-11-15 Thread Blason R
Hmmm - Ok let me try doing that. Thanks for letting me know On Fri, Nov 15, 2024 at 3:43 PM Lee wrote: > > On Thu, Nov 14, 2024 at 1:48 AM Blason R wrote: > > > > Hello Team, > > > > I am encountering an unusual problem. I am using BIND version BIND > > 9.18.19-1+ubuntu22.04.1+isc+1-Ubuntu and h

Re: BIND RPZ is not blocking A record

2024-11-15 Thread Lee
On Thu, Nov 14, 2024 at 1:48 AM Blason R wrote: > > Hello Team, > > I am encountering an unusual problem. I am using BIND version BIND > 9.18.19-1+ubuntu22.04.1+isc+1-Ubuntu and have configured BIND RPZ. My > objective is to block access to app.hubspot.com, for which I have > established a zone. >

Re: BIND RPZ is not blocking A record

2024-11-14 Thread Nick Tait via bind-users
Remember that when you update a zone you need to increase the serial number (in SOA record) and tell BIND to reload the zone - e.g. run “rndc reload”. Nick. > On 15 Nov 2024, at 6:30 PM, Blason R wrote: > > Even I tried that but still no luck > > $TTL 180 > @ IN SOA ns

Re: BIND RPZ is not blocking A record

2024-11-14 Thread Blason R
Even I tried that but still no luck $TTL 180 @ IN SOA ns1.custom.block. ns1.custom.block. ( 2006060301 21600 3600 604800 3600 ) IN NSns1.custom.block. ns1.custom.block. IN A 172.1.254.243 wg.custom.block.IN A 172.1.254.243 app.hubspot.com

Re: BIND RPZ is not blocking A record

2024-11-14 Thread Nick Tait via bind-users
On 14/11/2024 7:48 pm, Blason R wrote: And here is zone file $TTL 180 @ IN SOA ns1.custom.block. ns1.custom.block. ( 2006060301 21600 3600 604800 3600 ) IN NSns1.custom.block. ns1.custom.block. IN A 172.1.xx.xx wg.custom.block.IN A 172

Re: BIND RPZ is not blocking A record

2024-11-14 Thread Blason R
That's my nginx load balancer ip. Surprisingly this happens only with this domain. On Thu, Nov 14, 2024, 17:30 Peter Davies wrote: > Hi Blason, >Your configuration looks correct, though BIND will try to resolve the > "wg.custom.block" > through your forwarders. > > What reply do you get from

Re: BIND RPZ is not blocking A record

2024-11-14 Thread Peter Davies
Hi Blason, Your configuration looks correct, though BIND will try to resolve the "wg.custom.block" through your forwarders. What reply do you get from: dig @172.1.254.243 custom.block soa /Peter -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list