Re: DDOS prevention - how to restrict queries to hint (root) zones?

2009-02-03 Thread Mark Andrews
In message 1233658532.12933.42.ca...@muccalla.uninsubria.it, MAtteo HCE Valsa sna writes: hi all, We run BIND 9.3.4-P1.1 on Debian GNU/Linux 4.0 (using the distribution's package), that do both recursive queries for internal clients (with proper allow-recursion clause) and authoritative

Re: DDOS prevention - how to restrict queries to hint (root) zones?

2009-02-03 Thread David Forrest
On Tue, 3 Feb 2009, Mark Andrews wrote: In message 1233658532.12933.42.ca...@muccalla.uninsubria.it, MAtteo HCE Valsa sna writes: hi all, We run BIND 9.3.4-P1.1 on Debian GNU/Linux 4.0 (using the distribution's package), that do both recursive queries for internal clients (with proper

DDOS prevention - how to restrict queries to hint (root) zones?

2009-02-03 Thread MAtteo HCE Valsasna
hi all, We run BIND 9.3.4-P1.1 on Debian GNU/Linux 4.0 (using the distribution's package), that do both recursive queries for internal clients (with proper allow-recursion clause) and authoritative servers for the institution's domain. There are reports of DDOS attacks based on DNS requests for