# notify no;
#};
-// Unfortunately, AFAICT we need to list the Linode IPs as an ACL (so they
-// can make the requests) *and* as masters (so they get the notify).
+// Unfortunately, AFAICT we need to list the Linode IPs as an ACL (so they can
+// make the requests) *and* as masters (so they get the notify --
+// secondaries-only, not the importers).
acl "linode" {
// Linode
// https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#operate-as-a-secondary-read-only-dns-service
2600:3c02::a;
2600:3c03::a;
2a01:7e00::a;
- // Import
- // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#import-a-dns-zone
- 96.126.114.97;
- 96.126.114.98;
- 2600:3c00::5e;
- 2600:3c00::5f;
};
// The actual ACL building blocks
acl "transfer-allowed" {
- localhost;
207.29.250.54; // ???
- 18.4.60.36; // charon
- 18.49.3.1; // charon4
- 18.25.131.1; // charon4
+ 18.4.60.36; // charon (SIPB-DNS)
+ 18.49.3.1; // charon4 (SIPB-DNS)
+ 18.25.131.1; // charon4 (SIPB-DNS)
74.207.246.137; // arctic
66.92.29.156; // copan
18.18.208.12; // olinda
- 18.25.129.162; // adehnert3.xvm
- 130.44.166.3; // DD
18.18.208.22; // chankillo
+ 18.25.129.162; // adehnert3.xvm
+ 73.149.184.234; // Fulgora Comcast IPv4
+ 2601:189:8482:d823:9d98:6c9f:ffec:ccdc; // Fulgora Comcast IPv6
+ 66.228.43.247; // goslar
"linode";
};
masters "primary-ns" {
- 18.18.208.22; // chankillo
+ //18.18.208.22; // chankillo
+ 66.228.43.247; // goslar
};
masters "secondary-ns" {
- 18.25.129.162; // adehnert3.xvm
- 18.18.208.12; // olinda
+ //18.25.129.162; // adehnert3.xvm
+ //18.18.208.12; // olinda
linode;
};
zone "dehnerts.com" IN {
type master;
file "/etc/bind/pri/combined-dehnerts.zone";
- #update-policy { grant * selfsub * A TXT;};
allow-update { none; };
allow-transfer { "transfer-allowed"; };
allow-query { any; };
// ALEX DEHNERT: slightly updated 2008-12-19
// ALEX DEHNERT: slightly updated 2010-03-01
- forward first;
- forwarders {
- 18.0.71.151;
- 18.0.70.160;
- 18.0.72.3;
- };
+ //forward first;
+ //forwarders {
+ // 18.0.71.151;
+ // 18.0.70.160;
+ // 18.0.72.3;
+ //};
//========================================================================
// If BIND logs error messages about the root key being expired,
// ALEX DEHNERT: copied from old arctic version on 2008-12-19
//ALEX DEHNERT: Security-related stuff:
// Secure(ish):
- allow-recursion { 18.18.208.12; 66.92.29.156; 66.92.29.144; 127.0.0.1; 192.168.0.0/16; 18.0.0.0/8; };
+ allow-recursion { 18.18.208.12; 66.92.29.156; 66.92.29.144; 127.0.0.1; 192.168.0.0/16; };
//allow-query { 66.92.29.156; 66.92.29.144; 127.0.0.1; };
allow-transfer { none; };