Summary with further Question: Domain Name System protection

vijay gill vgill at vijaygill.com
Tue Aug 17 19:21:15 UTC 2004


On Tue, Aug 17, 2004 at 03:57:17AM +0000, bmanning at vacation.karoshi.com wrote:

> > 5. 'bogon'in BIND configuration could be used to
> > filter requests from RFC1918 address;
> 
> 	this should be pushed to
> 	the router.  don't waste CPU cycles 
> 	on the Nameserver.

Hosts tend to be a faster writeoff cycle than routers in companies I've
worked at, therefore getting the benefit of moores law about 25% faster
than the routers.  Turn on firewalling in the host. That said, I do
filter 1918 at my edge.


/vijay



More information about the NANOG mailing list