From owner-freebsd-net@FreeBSD.ORG Mon Aug 28 19:53:43 2006 Return-Path: X-Original-To: freebsd-net@FreeBSD.org Delivered-To: freebsd-net@FreeBSD.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2591516A4DA; Mon, 28 Aug 2006 19:53:43 +0000 (UTC) (envelope-from jmg@hydrogen.funkthat.com) Received: from hydrogen.funkthat.com (gate.funkthat.com [69.17.45.168]) by mx1.FreeBSD.org (Postfix) with ESMTP id 36FB843D55; Mon, 28 Aug 2006 19:53:42 +0000 (GMT) (envelope-from jmg@hydrogen.funkthat.com) Received: from hydrogen.funkthat.com (m2hxxagoj2b04x8i@localhost.funkthat.com [127.0.0.1]) by hydrogen.funkthat.com (8.13.6/8.13.3) with ESMTP id k7SJreO1012726; Mon, 28 Aug 2006 12:53:40 -0700 (PDT) (envelope-from jmg@hydrogen.funkthat.com) Received: (from jmg@localhost) by hydrogen.funkthat.com (8.13.6/8.13.3/Submit) id k7SJreQM012725; Mon, 28 Aug 2006 12:53:40 -0700 (PDT) (envelope-from jmg) Date: Mon, 28 Aug 2006 12:53:39 -0700 From: John-Mark Gurney To: Julian Elischer Message-ID: <20060828195339.GF37035@funkthat.com> Mail-Followup-To: Julian Elischer , Doug Barton , FreeBSD Net References: <44EF6E18.6090905@elischer.org> <44F3429F.6050204@FreeBSD.org> <44F344FA.1000408@elischer.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <44F344FA.1000408@elischer.org> User-Agent: Mutt/1.4.2.1i X-Operating-System: FreeBSD 5.4-RELEASE-p6 i386 X-PGP-Fingerprint: B7 EC EF F8 AE ED A7 31 96 7A 22 B3 D8 56 36 F4 X-Files: The truth is out there X-URL: http://resnet.uoregon.edu/~gurney_j/ X-Resume: http://resnet.uoregon.edu/~gurney_j/resume.html Cc: FreeBSD Net , Doug Barton Subject: Re: possible patch for implementing split DNS X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: John-Mark Gurney List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 28 Aug 2006 19:53:43 -0000 Julian Elischer wrote this message on Mon, Aug 28, 2006 at 12:33 -0700: > ALmost all other services (e.g. inetd,natd,sshd, etc.etc.) allow you to > specify a different config file > so that you can supply different services to theinside and outside but > it all falls appart > if they still are forced to use the same DNS server and can not provide > a differentiated service > for that reason. Why not put one of the two in side a jail (I think someone else mentioned this), or chroot'd environment where it can pick up a different resolv.conf? -- John-Mark Gurney Voice: +1 415 225 5579 "All that I will do, has been done, All that I have, has not."