By default, bind will allow recursive queries for lookups on other domains that are not master zones on the name server.
This presents some PCI compliance issues and some informational vulnerabilities (allowing third parties to query the nameserver).
It is important to restrict who can perform DNS queries, in addition to what is allowed to be queried. If this DNS server is only meant to be recursively queried by internal users for third-party domains, then there is no reason to allow the general internet to also perform queries against it. If the server is meant only to act as a nameserver for specific domains, then recursive queries should be disabled as it is unnecessary for the server to resolve anything other than its own domains.
To disable recursive queries, add the following to the options section of named.conf:
allow-transfer {“none”;};
allow-recursion {“none”;};
recursion no;
Then restart the named service and dig at the name server to ensure the changes have taken effect.
Tweet
Solid blog. I got a lot of great info. I’ve been watching this technology for awhile. It’s interesting how it keeps varying, yet some of the core components remain the same. Have you seen much change since Google made their latest acquisition in the arena?
very use full information. thank you.
Have you ever considered adding more videos to your blog posts to keep the readers more entertained? I mean I just read through the entire article of yours and it was quite good but since I’m more of a visual learner,I found that to be more helpful well let me know how it turns out. This is good…thanks for sharing
I wanted to thank you for this great read!! I definitely enjoyed every little bit of it. I have you bookmarked your site to check out the latest stuff you post.
Great information! I’ve been looking for something like this for a while now. Thanks!
I wanted to thank you for this great read!! I definitely enjoyed every little bit of it. I have you bookmarked your site to check out the latest stuff you post.
Hi, good day. Wonderful post. You have gained a new subscriber. Pleasee continue this great work and I look forward to more of your great blog posts.