Re: [opensuse] Ipv6 and dns



James Knott wrote:

Carlos E. R. wrote:
I have a local dns server (bind 9), and I wonder if there is some
setting so that it doesn't do any IPv6 query to outside. Would that
be AAAA records? Perhaps is it possible to block such queries in the
firewall?

I don't know about bind, but I doubt you could filter it at the
firewall, as you'd then have to filter all DNS requests.

Not necessarily - iptables has content inspection, so it might be
possible to identify individual AAAA queries. The question is if
dropping such queries wouldn't just mean longer processing time?


--
Per Jessen, Zürich (17.3°C)

--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
To contact the owner, e-mail: opensuse+owner@xxxxxxxxxxxx



Relevant Pages

  • Re: When does BIND send queries with DO flag enabled?
    ... client workstations are XPSP3, and NONE of the queries coming from those ... DNSSEC capable. ... fixing the firewall is the only ...
    (comp.protocols.dns.bind)
  • Re: Portscan from DNS server?
    ... You need to allow TCP/UDP traffic from port 53 ... >> through your firewall for DNS queries to work properly. ... >malfunction (DNS lookup failure) during the hours when ZoneAlarm ...
    (comp.security.firewalls)
  • Re: Portscan from DNS server?
    ... You need to allow TCP/UDP traffic from port 53 ... >> through your firewall for DNS queries to work properly. ... >malfunction (DNS lookup failure) during the hours when ZoneAlarm ...
    (comp.security.firewalls)
  • Re: disable dnssec in bind resolver
    ... In message, Doug Barton writes: ... The resolver works. ... queries and falls back to the old style queries. ... The OP's problem was that his firewall blocked anything with DO=1. ...
    (comp.protocols.dns.bind)
  • Re: disable dnssec in bind resolver
    ... In message, Mark Andrews writes: ... queries and falls back to the old style queries. ... The OP's problem was that his firewall blocked anything with DO=1. ... Seymour St., Dundas Valley, NSW 2117, Australia ...
    (comp.protocols.dns.bind)