<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Restricting zone transfers with IP addresses in BIND DNS Server</title> <atom:link href="http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html/feed" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html</link> <description>This is a Linux sys admin journal by Vivek about sys admin work, Linux tips &#38; tricks, hacks, news and more.</description> <lastBuildDate>Fri, 10 Feb 2012 20:37:43 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: äijö</title><link>http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html#comment-146475</link> <dc:creator>äijö</dc:creator> <pubDate>Sun, 28 Dec 2008 18:26:49 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html#comment-146475</guid> <description>Ulrich: are you able to recognize authorative and resolve DNS server? You cannot run both on this same IP address, so if you need authorative server for your domains, you should restrict zone transfers only to slaves. If it&#039;s necessary to having resolver in local network, run it on local address.</description> <content:encoded><![CDATA[<p>Ulrich: are you able to recognize authorative and resolve DNS server? You cannot run both on this same IP address, so if you need authorative server for your domains, you should restrict zone transfers only to slaves. If it&#8217;s necessary to having resolver in local network, run it on local address.</p> ]]></content:encoded> </item> <item><title>By: vivek</title><link>http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html#comment-141415</link> <dc:creator>vivek</dc:creator> <pubDate>Tue, 16 Oct 2007 12:36:53 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html#comment-141415</guid> <description>Yes this information is publicly available through BIND server, there is no reason to make an attacker&#039;s life easier. There is no legitimate reason for anyone outside your organization to transfer your zones in bulk.</description> <content:encoded><![CDATA[<p>Yes this information is publicly available through BIND server, there is no reason to make an attacker&#8217;s life easier. There is no legitimate reason for anyone outside your organization to transfer your zones in bulk.</p> ]]></content:encoded> </item> <item><title>By: Ulrich Wisser</title><link>http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html#comment-141414</link> <dc:creator>Ulrich Wisser</dc:creator> <pubDate>Tue, 16 Oct 2007 11:36:23 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/howto-restrict-unauthorized-zone-transfers-dns-bind.html#comment-141414</guid> <description>Hi,
why would you like to restrict your zone transfer? You will allow any resolver to ask for the same data, but you won&#039;t allow a transfer? I suggest you put only public data in your zone file and don&#039;t care about the zone transfer. If you have to have private data in a zone file, set up an internal DNS master (or use split DNS) with a private zone file and restrict access for resolvers and zone transfer.
Ulrich</description> <content:encoded><![CDATA[<p>Hi,</p><p>why would you like to restrict your zone transfer? You will allow any resolver to ask for the same data, but you won&#8217;t allow a transfer? I suggest you put only public data in your zone file and don&#8217;t care about the zone transfer. If you have to have private data in a zone file, set up an internal DNS master (or use split DNS) with a private zone file and restrict access for resolvers and zone transfer.</p><p>Ulrich</p> ]]></content:encoded> </item> </channel> </rss>
