Re: bind configuration help

2009-11-12 Thread Laurent CARON
On 12/11/2009 00:32, Błażej Ślusarek wrote: Hi, first of all thanks to everyone for the interest and for pointing me out my mistakes :) I've already changed recursion and transfer to trusted acls. But unfortunately, I've been administering this server for a short time and as I'm reading more and

Re: bind configuration help

2009-11-11 Thread Błażej Ślusarek
formation anyway with enough digging but why make it easy for him? > > -Original Message- > From: bind-users-boun...@lists.isc.org > [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Kevin Darcy > Sent: Wednesday, November 11, 2009 12:53 PM > To: bind-users@lists.

Re: bind configuration help

2009-11-11 Thread Kevin Darcy
ous state of affairs. -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Kevin Darcy Sent: Wednesday, November 11, 2009 12:53 PM To: bind-users@lists.isc.org Subject: Re: bind configuration help Holger Honert wrote: Security

RE: bind configuration help

2009-11-11 Thread Jeff Lightner
nough digging but why make it easy for him? -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Kevin Darcy Sent: Wednesday, November 11, 2009 12:53 PM To: bind-users@lists.isc.org Subject: Re: bind configuration help Holger Honert

Re: bind configuration help

2009-11-11 Thread Kevin Darcy
Holger Honert wrote: Security issues! Usually you only want *trusted* clients to use your server recursively. And you don't really want to allow *any* fetching your hosted zones for doing something bad, i.e. getting (unwanted!) infos over your network and infrastructure. If the infos are publ

Re: bind configuration help

2009-11-11 Thread Holger Honert
Sorry about that, but I only pressed the button "answer all" and thunderbird did the rest automagically ;-) . Regards SIGNAL Krankenversicherung a. G., Sitz: Dortmund, HR B 2405, AG Dortmund IDUNA Vereinigte Lebensversicherung aG für Handwerk, Handel und Gewerbe, Sitz: Hamburg, HR B 2740, AG Ha

RE: bind configuration help

2009-11-11 Thread Jukka Pakkanen
From: Holger Honert [mailto:holger.hon...@signal-iduna.org] .. *Please be carefull when quoting, this was not me: Jukka Pakkanen schrieb: Sorry, but could You specify more accurately what is "bad" ? This is my first bind configuration, so probably I've made some mistakes, but I'd

Re: bind configuration help

2009-11-11 Thread Holger Honert
Security issues! Usually you only want *trusted* clients to use your server recursively. And you don't really want to allow *any* fetching your hosted zones for doing something bad, i.e. getting (unwanted!) infos over your network and infrastructure. Regards Holger Jukka Pakkanen schrieb: > S

RE: bind configuration help

2009-11-11 Thread Jukka Pakkanen
Sorry, but could You specify more accurately what is "bad" ? This is my first bind configuration, so probably I've made some mistakes, but I'd like to do it the right way in the end.:) On Tue, Nov 10, 2009 at 11:19 PM, Laurent CARON wrote: >> allow-recursion { any; }; > > bad > >> allow-

Re: bind configuration help

2009-11-10 Thread Błażej Ślusarek
Sorry, but could You specify more accurately what is "bad" ? This is my first bind configuration, so probably I've made some mistakes, but I'd like to do it the right way in the end.:) On Tue, Nov 10, 2009 at 11:19 PM, Laurent CARON wrote: > On 10/11/2009 23:07, Błażej Ślusarek wrote: >> >> Hello

Re: bind configuration help

2009-11-10 Thread Kevin Darcy
Laurent CARON wrote: On 10/11/2009 23:07, Błażej Ślusarek wrote: Hello, Hi I'd like to ask for help in setting up my DNS server. When I start the server, everything is fine, but only for some time. After the "some time" passes, my external domain name cannot be resolved from anywhere on the

Re: bind configuration help

2009-11-10 Thread Laurent CARON
On 10/11/2009 23:07, Błażej Ślusarek wrote: Hello, Hi I'd like to ask for help in setting up my DNS server. When I start the server, everything is fine, but only for some time. After the "some time" passes, my external domain name cannot be resolved from anywhere on the Internet. When I resta