aboutsummaryrefslogtreecommitdiff
path: root/bind/conf/named.conf
diff options
context:
space:
mode:
authorMike Crute <mike@crute.us>2019-12-30 22:17:17 +0000
committerMike Crute <mike@crute.us>2019-12-30 22:17:17 +0000
commitdab2dedf68d07c506e569b69fdb9c454244a4b4f (patch)
tree85277d9d22a40062e04b23e09de8f7fdf27d3844 /bind/conf/named.conf
parent637c1c1f23ed912f47a2aa16218e4cfac6bc9c0a (diff)
downloaddockerfiles-dab2dedf68d07c506e569b69fdb9c454244a4b4f.tar.bz2
dockerfiles-dab2dedf68d07c506e569b69fdb9c454244a4b4f.tar.xz
dockerfiles-dab2dedf68d07c506e569b69fdb9c454244a4b4f.zip
Tune BIND settings
Diffstat (limited to 'bind/conf/named.conf')
-rw-r--r--bind/conf/named.conf23
1 files changed, 22 insertions, 1 deletions
diff --git a/bind/conf/named.conf b/bind/conf/named.conf
index 071cea7..88e45d8 100644
--- a/bind/conf/named.conf
+++ b/bind/conf/named.conf
@@ -1,4 +1,4 @@
1// vi:ft=named 1// vi:ft=named noexpandtab
2 2
3include "/etc/bind/rndc.key"; 3include "/etc/bind/rndc.key";
4 4
@@ -16,6 +16,7 @@ options {
16 dnssec-validation no; 16 dnssec-validation no;
17 17
18 auth-nxdomain no; # conform to RFC1035 18 auth-nxdomain no; # conform to RFC1035
19 notify master-only; # don't send NOTIFY from slaves
19 20
20 listen-on { any; }; 21 listen-on { any; };
21 listen-on-v6 { any; }; 22 listen-on-v6 { any; };
@@ -23,6 +24,12 @@ options {
23 version none; 24 version none;
24 hostname none; 25 hostname none;
25 26
27 allow-update-forwarding { any; };
28
29 allow-notify {
30 all-masters;
31 };
32
26 allow-recursion { 33 allow-recursion {
27 internal-nets; 34 internal-nets;
28 localhost; 35 localhost;
@@ -38,6 +45,11 @@ options {
38 transfers-out 30; 45 transfers-out 30;
39}; 46};
40 47
48statistics-channels {
49 inet 127.0.0.1 port 8053 allow { localhost; };
50 inet ::1 port 8053 allow { localhost; };
51};
52
41controls { 53controls {
42 inet 127.0.0.1 allow { localhost; } keys { "rndc-key"; }; 54 inet 127.0.0.1 allow { localhost; } keys { "rndc-key"; };
43 inet ::1 allow { localhost; } keys { "rndc-key"; }; 55 inet ::1 allow { localhost; } keys { "rndc-key"; };
@@ -57,4 +69,13 @@ acl internal-nets {
57 192.168.255.0/24; // Local Docker Bridge 69 192.168.255.0/24; // Local Docker Bridge
58}; 70};
59 71
72acl all-masters {
73 // PDX1 Gateway
74 50.112.45.116;
75 54.148.70.70;
76 172.16.18.73;
77 172.16.18.52;
78 2600:1f14:f39:e000:9fb5:8745:4eec:28b8;
79};
80
60include "/etc/bind/local/zones.conf"; 81include "/etc/bind/local/zones.conf";