R: RPZ and client matching

2015-05-10 Thread Job
Hi Chris,

Have that view forward to the main view, using any of a variety of methods. 
For example, forward to the loopback address, which doesn't match the new 
view's match-clients ACL.

So do you think, without using the in-view clause because it not supports 
RPZ, is there a way to load dns-blacklists once, using more views?

Could you please explain me better the forward zones in the same dns server?

Thank you!
Francesco
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


R: RPZ and client matching

2015-05-10 Thread Job
Hello,

You can use a combination of rpz-client-ip. trigger and
rpz-passthru. action to achieve either effect.

i notice i can define a policy and then, with rpz-passtru, i can make 
exceptions for client.
But i did not find how to write a policy, for example resolve with 127.0.0.1 
*.playboy.com, and assigning this policy to one or more client ip.

Is there a way?

I would not like to use views because, behind some blacklists some millions of 
records long, without the possibility to reuse rpz-zone between views (in-view 
is not working with rpz), memory overuse would be a big problem!

Thank you again, Francesco
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


Re: [bind-users] Re: BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2015-05-10 Thread /dev/rob0
On Sun, May 10, 2015 at 02:39:04AM +, Evan Hunt wrote:
 On Sat, May 09, 2015 at 04:56:08PM -0500, Jerry K wrote:
  Was going thru some old messages, and came across this one
  about generating the ARM doc as HTML.
  
  Just wondering if anything ever became of it?
 
 The ARM is generated as HTML now, but the request in that thread
 was to add better anchor tags for each option, so you could look
 up Bv9ARM.ch06.html#response-policy or whatever, and be taken
 to the corresponding section of the ARM.
 
 Good idea, nobody's done it yet.

Oops, sorry.  When I suggested it I was unemployed, and now 
[thankfully] am not.  $Dayjob keeps me busy, but now I have more
clue about the docbook, so I'll try to do what I can.
-- 
  http://rob0.nodns4.us/
  Offlist GMX mail is seen only if /dev/rob0 is in the Subject:
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users