10 Jun
2013
10 Jun
'13
2:35 p.m.
On Jun 11, 2013, at 1:31 PM, Dave Mill wrote:
There's going to be quite a challenge to lock those open resolvers down, and we're debating how to do it at the moment
ACLs.
DNS queries from the outside shouldn't be allowed to hit recursors, which should be functionally separated from authoritative servers:
https://www.box.com/s/72bccbac1636714eb611
-----------------------------------------------------------------------
Roland Dobbins