@@ -630,9 +630,9 @@ options
630
630
datasize default;
631
631
datasize unlimited;
632
632
deallocate-on-exit no; // ancient
633
- deny-answer-addresses { example.net; 127.0.0.1/8; };
633
+ deny-answer-addresses { " example.net" ; 127.0.0.1/8; };
634
634
deny-answer-addresses { "example.net"; };
635
- deny-answer-addresses { acl_ntwk; };
635
+ deny-answer-addresses { " acl_ntwk" ; };
636
636
deny-answer-addresses { 123.123.123.123; };
637
637
deny-answer-addresses { 123.123.123.123; } except-from { "localhost"; 1.2.3.4; };
638
638
deny-answer-addresses { 123.123.123.123; }
@@ -645,7 +645,7 @@ options
645
645
1.2.3.4;
646
646
};
647
647
deny-answer-aliases { "example.net"; };
648
- deny-answer-aliases { acl_ntwk; };
648
+ deny-answer-aliases { " acl_ntwk" ; };
649
649
deny-answer-aliases { "example.org"; } except-from { "localhost"; 1.2.3.4; };
650
650
deny-answer-aliases { "cname.example.com."; }
651
651
except from {
@@ -664,13 +664,14 @@ options
664
664
dns64 fe08::1/5 { mapped { any; }; }; // default
665
665
dns64 fe08::1/5 { recursive-only no; }; // default
666
666
dns64 fe08::1/5 {
667
- break-dnssec yes;
668
- recursive-only no;
669
- suffix ::ffff:0.0.0.0/96;
670
- exclude { ff::; };
671
- mapped { none; };
672
- recursive-only yes;
673
- };
667
+ break-dnssec yes ;
668
+ recursive-only no ;
669
+ suffix ::ffff:0.0.0.0/96 ;
670
+ suffix ::ffff:0.0.0.0/96 ;
671
+ exclude { ff:: ; } ;
672
+ mapped { none; } ;
673
+ recursive-only yes ;
674
+ } ;
674
675
dns64-contact "test.example.org";
675
676
dns64-server 'test.example.net.';
676
677
dnskey-sig-validity 1;
@@ -704,14 +705,13 @@ options
704
705
dnstap-identity example.com;
705
706
dnstap-output unix quotedstring size unlimited version unlimited suffix increment;
706
707
dnstap-output
707
- unix quotedstring
708
+ unix " quotedstring"
708
709
size unlimited
709
- version unlimited
710
- suffix increment;
710
+ versions unlimited suffix increment;
711
711
dnstap-output
712
712
file "/var/run/bind/dnstap-out.sock"
713
713
size unlimited
714
- version unlimited
714
+ versions unlimited
715
715
suffix increment;
716
716
dnstap-version none;
717
717
dnstap-version quoted_string;
@@ -756,7 +756,7 @@ options
756
756
glue-cache yes;
757
757
has-old-clients no; // ancient
758
758
heartbeat-interval 40320;
759
- host-statistics "/tmp/junk" ;
759
+ host-statistics no ;
760
760
host-statistics-max 15;
761
761
hostname none;
762
762
inline-signing yes;
@@ -800,6 +800,7 @@ include "/var/lib/dhcp/bind-listen-on-ip.conf";
800
800
max-transfer-time-in 100;
801
801
max-transfer-time-out 100;
802
802
max-udp-size 1490;
803
+ max-udp-size 490;
803
804
max-zone-ttl 123123;
804
805
max-zone-ttl unlimited;
805
806
memstatistics yes;
@@ -985,7 +986,7 @@ include "/var/lib/dhcp/bind-listen-on-ip.conf";
985
986
treat-cr-as-space no; // ancient
986
987
trust-anchor-telemetry true;
987
988
try-tcp-refresh true;
988
- # trust-anchors { example.net initial-ds 1 1 1 yes; };
989
+ trust-anchors { example.net initial-ds 1 1 1 yes; };
989
990
update-check-ksk true;
990
991
use-alt-transfer-source yes;
991
992
use-id-pool no; // ancient
@@ -1016,15 +1017,16 @@ server 192.1.2.324/24 {
1016
1017
edns yes;
1017
1018
edns-version 15;
1018
1019
keys key_id;
1019
- max-udp-size 4096;
1020
+ max-udp-size 4096
1021
+ max-udp-size x096xx
1020
1022
notify-source 1.1.1.1 port * dscp 53;
1021
1023
notify-source-v6 ff08::1 port * dscp 53;
1022
1024
padding 1490;
1023
1025
provide-ixfr no;
1024
1026
query-source 1.1.1.1 port * dscp 53;
1025
1027
query-source-v6 ff08::1 port * dscp 53;
1026
1028
request-expire yes;
1027
- request-ixfr yes;
1029
+ request-ixfr yes;
1028
1030
request-nsid yes;
1029
1031
request-sit no; // obsolete
1030
1032
send-cookie yes;
@@ -1035,7 +1037,7 @@ server 192.1.2.324/24 {
1035
1037
transfer-source * port * dscp 63;
1036
1038
transfer-source-v6 fe80:1::127.0.0.1 port * dscp 63;
1037
1039
transfer-source-v6 fe08:1::127.0.0.1 port 53;
1038
- transfers 15;
1040
+ transfers 15;
1039
1041
};
1040
1042
1041
1043
statistics-channels {
@@ -1160,6 +1162,23 @@ view "redview" {
1160
1162
dnssec-update-mode no-resign;
1161
1163
dnssec-validation True;
1162
1164
dnstap { all; };
1165
+ dnstap { all query; };
1166
+ dnstap { all response; };
1167
+ dnstap { auth; };
1168
+ dnstap { auth query; };
1169
+ dnstap { auth response; };
1170
+ dnstap { client; };
1171
+ dnstap { client query; };
1172
+ dnstap { client response; };
1173
+ dnstap { forwarder; };
1174
+ dnstap { forwarder query; };
1175
+ dnstap { forwarder response; };
1176
+ dnstap { resolver; };
1177
+ dnstap { resolver query; };
1178
+ dnstap { resolver response; };
1179
+ dnstap { update; };
1180
+ dnstap { update query; };
1181
+ dnstap { update response; };
1163
1182
dual-stack-servers { example.com; } ;
1164
1183
dual-stack-servers port 123{example.com ;} ;
1165
1184
dual-stack-servers { example.com port 11111; };
@@ -1216,11 +1235,17 @@ view "redview" {
1216
1235
max-refresh-time 53;
1217
1236
max-retry-time 53;
1218
1237
max-stale-ttl 53;
1219
- max-transfer-idle-in 53;
1238
+ max-transfer-idle-in 53; // my inline comment seems to work now.
1220
1239
max-transfer-idle-out 53;
1221
1240
max-transfer-time-in 53;
1222
1241
max-transfer-time-out 53;
1223
- max-udp-size 53;
1242
+ max-udp-size 4096;
1243
+ max-udp-size 1024;
1244
+ max-udp-size 512;
1245
+ max-udp-size 0;
1246
+ max-udp-size 1;
1247
+ max-udp-size 4097;
1248
+ max-udp-size x;
1224
1249
max-zone-ttl unlimited;
1225
1250
message-compression no;
1226
1251
min-cache-ttl 53;
0 commit comments