[Opendnssec-user] OpenDNSSEC & BIND

Ramanou Biaou ramanou at netim.com
Fri Jan 31 13:26:16 UTC 2014


Dear all
Can you give me more details on the implementation of the "view"

Jakob, I did not understand what you sent

For my opendnssec sending zone signed  with XFRD in to my secondary. But 
that the primary  leisure unsigned zone file not receiving the zone 
signed by opendnssec
I also use TSIG for transfer zone.

Thank you!
Ramanou

Le 31/01/2014 13:36, Jakob Schlyter a écrit :
> On 31 jan 2014, at 13:33, Gavin Brown <gavin.brown at centralnic.com> wrote:
>
>> I recently built a BIND config very similar to this. Rather than using
>> match-clients in each view, I gave each view its own IP address and used
>> match-destinations.
>>
>> This means you can query the signed and unsigned views remotely, which
>> is handy for debugging and monitoring.
> Yes, that is a much nicer solution. You can also select view based on the TSIG used in the DNS query, a solution that could confuse even the most experienced DNS administrator :-)
>
> 	jakob
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20140131/ef4df2b9/attachment.htm>


More information about the Opendnssec-user mailing list