Re: secure zone transfer and dynamic update

This is a discussion on Re: secure zone transfer and dynamic update within the Bind Users forums, part of the DNS and Related Forums category; saravanan ganapathy <sarav_gsa@yahoo.com> wrote: > Hai, > I have configured bind9.2 on my debian woody....


Go Back   Usenet Forums > DNS and Related Forums > Bind Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-29-2004
phn@icke-reklam.ipsec.nu
 
Posts: n/a
Default Re: secure zone transfer and dynamic update

saravanan ganapathy <sarav_gsa@yahoo.com> wrote:
> Hai,
> I have configured bind9.2 on my debian woody.TSIG
> also configured for zone Txfr and ddns update.


> My config file as


> zone "abc.com" {
> type master;
> file "abc";
> allow-transfer {key abc.com;};
> allow-update { key abc.com;};
> };
> server 50.50.50.1 {
> keys { abc.com ;};
> };
> key "abc.com." {
> algorithm HMAC-MD5;
> secret "aasfsv131414";
> };


> I also configured slave server with this TSIG.It works
> well.
>
> My Problem:
> ------------
> The master server gives the zone data to any server
> which have the same TSIG key, though I have specified
> the slave server ip address only in the master server.


> The server should responds for zone txfr only when
> both the ip address and TSIG key matches.


> How to configure this?


> I have the same problem with ddns update also.


> Pls guide me


> Note :


> Even " allow-transfer {key abc.com;50.50.50.1;}; "
> doesn't help


No surprice, this represents a logical or statement.

See the section 6.2.24.4. Dynamic Update Policies which might
give you some more control, the "xfer-policy" command seems
unimplemented ( Jim, are you taking notes ?)

> Sarav










> __________________________________________________
> Do You Yahoo!?
> Tired of spam? Yahoo! Mail has the best spam protection around
> http://mail.yahoo.com



--
Peter Håkanson
IPSec Sverige ( At Gothenburg Riverside )
Sorry about my e-mail address, but i'm trying to keep spam out,
remove "icke-reklam" if you feel for mailing me. Thanx.

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:08 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0