Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 4 May 2001 18:49:50 +0200
From:      Edwin Groothuis <edwin@mavetju.org>
To:        Wayne Pascoe <wayne.pascoe@realtime.co.uk>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Purpose of serial number in zone files (BIND)
Message-ID:  <20010504184950.G50786@d9168.upc-d.chello.nl>
In-Reply-To: <m1lmodcdrk.fsf@zaphod.realtime.co.uk>; from wayne.pascoe@realtime.co.uk on Fri, May 04, 2001 at 04:52:47PM %2B0100
References:  <m1wv7xdww5.fsf@zaphod.realtime.co.uk> <20010504163252.D50786@d9168.upc-d.chello.nl> <m1k83xdvu3.fsf@zaphod.realtime.co.uk> <20010504160732.A1139@cartman.techsupport.co.uk> <m166fhdtyr.fsf@zaphod.realtime.co.uk> <20010504173201.E50786@d9168.upc-d.chello.nl> <m1lmodcdrk.fsf@zaphod.realtime.co.uk>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, May 04, 2001 at 04:52:47PM +0100, Wayne Pascoe wrote:
> Edwin Groothuis <edwin@mavetju.org> writes:
> > Why don't you let the DNS protocol handle the distribution towards
> > the slaves? Then you only have to worry about the creation on the
> > master. I really don't see the advantages of what you try to
> > accomplish.
> 
> That is one possiblity. But we can do database access over ssh
> tunnel. Also, I want to dissallow zone transfers by default for
> slightly increased security. AFAIK, some of the bind bugs have been
> related to zone transfers.

You can limit that with the "allow-transfer" statement.

Edwin

-- 
Edwin Groothuis   |              Personal website: http://www.MavEtJu.org
edwin@mavetju.org |           Interested in MUDs? Visit Fatal Dimensions:
------------------+                     http://FatalDimensions.nl.eu.org/

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010504184950.G50786>