Per Jessen wrote:
Richard Creighton wrote:
Jul 24 09:22:05 raid5 named[3935]: client 195.135.220.2#32768: query 'ns1.ricreig.com/AAAA/IN' denied Jul 24 09:22:05 raid5 named[3935]: client 195.135.220.2#32768: query 'ns2.ricreig.com/AAAA/IN' denied Jul 24 09:22:05 raid5 named[3935]: client 195.135.221.2#32768: query 'ns1.ricreig.com/AAAA/IN' denied Jul 24 09:22:05 raid5 named[3935]: client 195.135.221.2#32768: query 'ns2.ricreig.com/AAAA/IN' denied Jul 24 09:22:06 raid5 named[3935]: client 195.135.220.15#32768: query 'ns1.ricreig.com/AAAA/IN' denied Jul 24 09:22:06 raid5 named[3935]: client 195.135.220.15#32768: query 'ns2.ricreig.com/AAAA/IN' denied Jul 24 09:22:06 raid5 named[3935]: client 195.135.220.15#32768: query 'ns1.ricreig.com/AAAA/IN' denied Jul 24 09:22:06 raid5 named[3935]: client 195.135.220.15#32768: query 'ns2.ricreig.com/AAAA/IN' denied
195.135.220.2 is a SUSE name or mail-server or both. 195.135.221.2 is a SUSE name server. 195.135.220.15 is a SUSE name server.
Why are you refusing that lookup? (I'm assuming 'ricreig.com' is your domain).
With your ban, you've prevented people from doing:
"dig @ns2.ricreig.com. ns1.ricreig.com. AAAA"
It's your choice of course ....
Bad choice of log exerpt....I have thousands of NON NS non MS queries and yes ricreig.com is my domain and I limit forwarded queries from out of localnet with 'options allow-recursion { localnet; }; ' in named.conf. -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org For additional commands, e-mail: opensuse+help@opensuse.org