RPZ Still Doing Recursive Lookups

2015-02-24 Thread Crist Clark
I am seeing that even with a zone included in an RPZ, the BIND server is still going out to the Internet to resolve the name. I was hoping the RPZ entry would stop processing short of that. I have some.bad.domain.tld returning NODATA. The client is getting the response I expect. The SOA is for

Re: RPZ Still Doing Recursive Lookups

2015-02-24 Thread Evan Hunt
On Tue, Feb 24, 2015 at 03:30:01PM -0800, Crist Clark wrote: I am seeing that even with a zone included in an RPZ, the BIND server is still going out to the Internet to resolve the name. I was hoping the RPZ entry would stop processing short of that. That's so named doesn't leak policy