Re: Adding subnet to firewalld drop zone

2018-08-12 Thread Dirk Gottschalk via users
Hi. Am Donnerstag, den 09.08.2018, 00:20 +0100 schrieb Danny Horne via users: > On 08/08/18 23:27, Dirk Gottschalk via users wrote: > > You have to find out whi issues the query. I would disable > > recursion at > > all except for the internal network. > > > > Find out who queries this domains an

Re: Adding subnet to firewalld drop zone

2018-08-08 Thread Danny Horne via users
On 08/08/18 23:27, Dirk Gottschalk via users wrote: > You have to find out whi issues the query. I would disable recursion at > all except for the internal network. > > Find out who queries this domains and answer witth NXDOMAIN, disabling > recursion would do thos. Blocking DNS queries if you are

Re: Adding subnet to firewalld drop zone

2018-08-08 Thread Danny Horne via users
On 08/08/18 23:27, Dirk Gottschalk via users wrote: > No, this is the queried DNS. It is the authoritative NS for the Domain > barracudacentral.org. > > Seems to be some kind of reverse entry which does not resolve > correctly. The Source for the query is not mentioned. The authotitative > can not

Re: Adding subnet to firewalld drop zone

2018-08-08 Thread Dirk Gottschalk via users
Hi. Am Mittwoch, den 08.08.2018, 22:27 +0100 schrieb Danny Horne via users: > Hi all, > > I've been trying to add a subnet to my firewalld drop zone because > queries from this subnet have been filling up my named logs and I've > had enough!! > > Based on research these are some assumptions I've