50 lines
		
	
	
		
			1.3 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			50 lines
		
	
	
		
			1.3 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
| options {
 | |
| 	directory "/var/cache/bind";
 | |
| 
 | |
| 	// If there is a firewall between you and nameservers you want
 | |
| 	// to talk to, you may need to fix the firewall to allow multiple
 | |
| 	// ports to talk.  See http://www.kb.cert.org/vuls/id/800113
 | |
| 
 | |
| 	// If your ISP provided one or more IP addresses for stable 
 | |
| 	// nameservers, you probably want to use them as forwarders.  
 | |
| 	// Uncomment the following block, and insert the addresses replacing 
 | |
| 	// the all-0's placeholder.
 | |
| 
 | |
| 	// forwarders {
 | |
| 	// 	0.0.0.0;
 | |
| 	// };
 | |
| 
 | |
| 	//========================================================================
 | |
| 	// If BIND logs error messages about the root key being expired,
 | |
| 	// you will need to update your keys.  See https://www.isc.org/bind-keys
 | |
| 	//========================================================================
 | |
| 	dnssec-validation auto;
 | |
| 
 | |
|    // Security options
 | |
|    listen-on {
 | |
|       127.0.0.1;
 | |
|       192.168.62.53;
 | |
|    };
 | |
|    allow-query {
 | |
|       127.0.0.1;
 | |
|       192.168.0.0/16;
 | |
|       10.0.0.0/8;
 | |
|       ::1;
 | |
|       2003:a:b3b:7900::/64;
 | |
|       fde2:8acd:e9d3::/64;
 | |
|    };
 | |
|    allow-recursion {
 | |
|       127.0.0.1;
 | |
|       192.168.0.0/16;
 | |
|       10.0.0.0/16;
 | |
|       ::1;
 | |
|       2003:a:b3b:7900::/64;
 | |
|       fde2:8acd:e9d3::/64;
 | |
|    };
 | |
|    allow-transfer { none; };
 | |
| 
 | |
| 	auth-nxdomain no;    # conform to RFC1035
 | |
|    listen-on-v6 { any; };
 | |
| };
 | |
| 
 |