Re: rpz fail

2019-08-27 Thread Lee
On 8/27/19, Tony Finch wrote: > Lee wrote: >> >> Can someone please explain why using this as my rpz zone does NOT >> block everything for *.2o7.net? >> >> 2o7.net CNAME . >> *.2o7.net CNAME . >> bcbsks.com.102.112.2o7.net CNAME . > > I suspect this is RPZ obeying the weird semantics of DNS wildc

Re: rpz fail

2019-08-27 Thread Tony Finch
Lee wrote: > > Can someone please explain why using this as my rpz zone does NOT > block everything for *.2o7.net? > > 2o7.net CNAME . > *.2o7.net CNAME . > bcbsks.com.102.112.2o7.net CNAME . I suspect this is RPZ obeying the weird semantics of DNS wildcard matching. The * only matches if the ans