Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 24 Jul 2001 11:47:38 -0400
From:      "alexus" <ml@db.nexgen.com>
To:        "Drew J. Weaver" <drew.weaver@thenap.com>, <freebsd-isp@freebsd.org>
Subject:   Re: Can someone do me a favor?
Message-ID:  <007a01c11457$f7385920$0d00a8c0@alexus>
References:  <B1A7D9973EBED3119ADD009027DC86492B0C3E@mailman.thenap.com>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
Can someone do me a favor?alexus@~# host 206.222.1.2
2.1.222.206.IN-ADDR.ARPA domain name pointer dns2.ee.net
alexus@~# host 206.222.1.3
3.1.222.206.IN-ADDR.ARPA domain name pointer dns3.ee.net
alexus@~# host 209.51.192.194
194.192.51.209.IN-ADDR.ARPA domain name pointer ns1.netservice.columbus-nap.net
alexus@~# host 206.222.1.4   
4.1.222.206.IN-ADDR.ARPA domain name pointer dns4.ee.net
alexus@~# host 209.51.193.2
2.193.51.209.IN-ADDR.ARPA domain name pointer dns1.ee.net
alexus@~# 

allow-query has nothin to do with trying to resolve it.. allow query only limit ips from using your ns

let's say if you only put your ip, you'll be the only one who can query your ns.. 

read how dns works..

  ----- Original Message ----- 
  From: Drew J. Weaver 
  To: 'freebsd-isp@freebsd.org' 
  Sent: Tuesday, July 24, 2001 9:48 AM
  Subject: Can someone do me a favor?


          try and resolve through any of these dns servers 
  206.222.1.2, 206.222.1.3, 209.51.192.194, 206.222.1.4, 209.51.193.2 

  I just implemented the allow-query command in my named.conf on all of these servers and much to my shygrin i dont think its actually limiting anything?

  It appears to still be wide open. 

  -Drew 








[-- Attachment #2 --]
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Can someone do me a favor?</TITLE>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2499.0" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT face="Courier New" size=2>alexus@~# host 
206.222.1.2<BR>2.1.222.206.IN-ADDR.ARPA domain name pointer 
dns2.ee.net<BR>alexus@~# host 206.222.1.3<BR>3.1.222.206.IN-ADDR.ARPA domain 
name pointer dns3.ee.net<BR>alexus@~# host 
209.51.192.194<BR>194.192.51.209.IN-ADDR.ARPA domain name pointer 
ns1.netservice.columbus-nap.net<BR>alexus@~# host 206.222.1.4&nbsp;&nbsp; 
<BR>4.1.222.206.IN-ADDR.ARPA domain name pointer dns4.ee.net<BR>alexus@~# host 
209.51.193.2<BR>2.193.51.209.IN-ADDR.ARPA domain name pointer 
dns1.ee.net<BR>alexus@~# </FONT></DIV>
<DIV><FONT face="Courier New" size=2></FONT>&nbsp;</DIV>
<DIV><FONT face="Courier New" size=2>allow-query has nothin to do with trying to 
resolve it.. allow query only limit ips from using your ns</FONT></DIV>
<DIV><FONT face="Courier New" size=2></FONT>&nbsp;</DIV>
<DIV><FONT face="Courier New" size=2>let's say if you only put your ip, you'll 
be the only one who can query your ns.. </FONT></DIV>
<DIV><FONT face="Courier New" size=2></FONT>&nbsp;</DIV>
<DIV><FONT face="Courier New" size=2>read how dns works..</FONT></DIV>
<DIV><FONT face="Courier New" size=2></FONT>&nbsp;</DIV>
<BLOCKQUOTE 
style="PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
  <DIV style="FONT: 10pt arial">----- Original Message ----- </DIV>
  <DIV 
  style="BACKGROUND: #e4e4e4; FONT: 10pt arial; font-color: black"><B>From:</B> 
  <A title=drew.weaver@thenap.com href="mailto:drew.weaver@thenap.com">Drew J. 
  Weaver</A> </DIV>
  <DIV style="FONT: 10pt arial"><B>To:</B> <A title=freebsd-isp@freebsd.org 
  href="mailto:'freebsd-isp@freebsd.org'">'freebsd-isp@freebsd.org'</A> </DIV>
  <DIV style="FONT: 10pt arial"><B>Sent:</B> Tuesday, July 24, 2001 9:48 
AM</DIV>
  <DIV style="FONT: 10pt arial"><B>Subject:</B> Can someone do me a favor?</DIV>
  <DIV><BR></DIV>
  <P>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <FONT size=2>try and resolve 
  through any of these dns servers</FONT> <BR><FONT size=2>206.222.1.2, 
  206.222.1.3, 209.51.192.194, 206.222.1.4, 209.51.193.2</FONT> </P>
  <P><FONT size=2>I just implemented the allow-query command in my named.conf on 
  all of these servers and much to my shygrin i dont think its actually limiting 
  anything?</FONT></P>
  <P><FONT size=2>It appears to still be wide open.</FONT> </P>
  <P><FONT size=2>-Drew</FONT> </P><BR><BR><BR><BR><BR></BLOCKQUOTE></BODY></HTML>
help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?007a01c11457$f7385920$0d00a8c0>