Re: Resolve some hosts thats are dnssec signed differently

2023-02-06 Thread Nick Tait via bind-users
Hi Matthias. It isn't clear whether the issue you're trying to solve is (a) avoiding DNS resolution going out then in to get to your authoritative servers, or (b) with resolved addresses of your servers being the public address which means that data packets sent to/from those servers are going

Re: Resolve some hosts thats are dnssec signed differently

2023-02-06 Thread Matthias Fechner
Hi Darren, Hi Nick, at first thanks a lot for your answer. I see that I have not explained my use-case detailed enough. I have bind running for domain fechner.net, but not at home and this server I think is here completely out of discussion. If I must not touch it, I do not want to touch it as i

Re: Resolve some hosts thats are dnssec signed differently

2023-02-06 Thread Nick Tait via bind-users
Hi Matthias. Using a Response Policy Zone on your internal DNS resolver, to change the answers to DNS queries for your domain from 195.30.95.36 to 192.168.0.1, sounds like the solution that most closely matches what you've described. Just be aware though, if you have any internal clients that