Re: Disabling RPZ for a few clients / views sharing zones

2014-02-06 Thread Jay Ford
On Thu, 6 Feb 2014, Chuck Anderson wrote: Neat. Is there any problem with using the exact same zone file in both views? I worry that one view might fight with the file from the other view... Oh yeah, sorry, I left that bit out. The slave files do need to be unique or they will over-write ea

Re: Disabling RPZ for a few clients / views sharing zones

2014-02-06 Thread Chuck Anderson
On Thu, Feb 06, 2014 at 02:49:03PM -0600, Jay Ford wrote: > I like the "trick" of having view A pull the zone from the real master & > notify view B, while view B pulls the zone locally from view A, using TSIG > keys to indicate the "other" view for the notify & transfer. > > Adapting your config,

Re: Disabling RPZ for a few clients / views sharing zones

2014-02-06 Thread Jay Ford
On Thu, 6 Feb 2014, Chuck Anderson wrote: On Thu, Feb 06, 2014 at 09:50:26AM -0800, Doug Barton wrote: On 02/06/2014 06:27 AM, Chuck Anderson wrote: I was kinda hoping that newer versions of BIND could share zones (with identical zone contents) between views without requiring the messy multiple

Re: Disabling RPZ for a few clients / views sharing zones

2014-02-06 Thread Evan Hunt
On Thu, Feb 06, 2014 at 03:10:03PM -0500, Chuck Anderson wrote: > > You have always been able to do this with include files. > > I'm not sure how this helps. If you do this: > > Then the "global" view sees updates to example.com quickly, as soon as > NOTIFY is sent by the master and the zone is

Re: Disabling RPZ for a few clients / views sharing zones

2014-02-06 Thread Chuck Anderson
On Thu, Feb 06, 2014 at 09:50:26AM -0800, Doug Barton wrote: > On 02/06/2014 06:27 AM, Chuck Anderson wrote: > >I was kinda hoping that newer > >versions of BIND could share zones (with identical zone contents) > >between views without requiring the messy multiple IP alias setup. > > You have alwa

Re: Disabling RPZ for a few clients / views sharing zones

2014-02-06 Thread Doug Barton
On 02/06/2014 06:27 AM, Chuck Anderson wrote: I was kinda hoping that newer versions of BIND could share zones (with identical zone contents) between views without requiring the messy multiple IP alias setup. You have always been able to do this with include files. hth, Doug

Disabling RPZ for a few clients / views sharing zones

2014-02-06 Thread Chuck Anderson
What is the best way to disable RPZ for a few clients (without forcing those clients to use different DNS server IPs)? I think I could create a new view that has all the same zones and zone contents except for the RPZ one. If I go this route, is it still required to set up per-view IP aliases on