<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Just a quick question about BIND]]></title><description><![CDATA[<p dir="auto">What are BIND Built-in ACL</p>
<p dir="auto">none - :)<br />
any - is the any defined 0.0.0.0/0<br />
localhost - is the localhost defined as 127.0.0.0/8 ?????<br />
localnets - ??????? local nets I use or the whole RFC1918 ????</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.netgate.com/topic/159983/just-a-quick-question-about-bind</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Jul 2026 18:54:55 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/159983.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 18 Jan 2021 08:18:18 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Just a quick question about BIND on Tue, 19 Jan 2021 17:41:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a> Hello</p>
<p dir="auto">I build my infrastructure It is not large in hardware perspective, but I've started to to integration of many apps that will have to have to be on a separate domains. Until now the internal resolver did the job, but now ... I need actual dns server.</p>
<p dir="auto">This is strange everywhere I open a discussion about BIND and DNS all I am getting is go somewhere else!!!!!! Never had a straight answer like this functions is for that that function is for that or if you want to do this just do this and this !!!! Never mind.</p>
<pre><code>Typically, you should isolate such a program, set up a test bed network and 'play' with.
</code></pre>
<p dir="auto">That's what I am doing right now I have a downstream network behind an other pfSense Firewall and that's where I am testing it. I also have a Ubuntu server behind this firewall with Virtualmin and BIND9 package installed with few test websites, but what I am trying to understand is some terminology and functions of BIND.</p>
<p dir="auto">So...</p>
<p dir="auto">I set in the Settings to listen on: all vlans, but there is an option on the bottom<br />
"Forwarder Configuration" should I set this "Forwarder IPs" to my upstream resolver or, if this option is not enabled it will simply look what DNS Servers set on System/General Settings ????</p>
<p dir="auto">and....</p>
<p dir="auto">In "Views" I have created and called "localview" where</p>
<p dir="auto">Recursion - Yes<br />
match-clients - Any<br />
but...<br />
allow-recursion - currently set to ANY, but this will be used for local zones isn't more secure to be set to "localnets" then "any" no matter if that is my downstream or upstream pfsense</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.netgate.com/post/957849</link><guid isPermaLink="true">https://forum.netgate.com/post/957849</guid><dc:creator><![CDATA[xlameee]]></dc:creator><pubDate>Tue, 19 Jan 2021 17:41:13 GMT</pubDate></item><item><title><![CDATA[Reply to Just a quick question about BIND on Tue, 19 Jan 2021 14:08:44 GMT]]></title><description><![CDATA[<p dir="auto">bind is comparable to apache2, nginx, postfix : these have huge range of possible configuration settings, hundreds of option that set or left to default.</p>
<p dir="auto">Typically, you should isolate such a program, set up a test bed network and 'play' with.<br />
At least, taht is what I would do. But I don't know what you want do, why etc etc.<br />
Take note that the Internet itself is based on these 4 program and there are billions of help pages, case studies, examples, questions/answers etc.<br />
So, it boils down to a "don't ask, just do it" ;)</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xlameee">@<bdi>xlameee</bdi></a> said in <a href="/post/957786">Just a quick question about BIND</a>:</p>
<blockquote>
<p dir="auto">I hope someone else ....</p>
</blockquote>
<p dir="auto">That some one else should be on site (for a while), or it would be some admin that accesses and knows your infrastructure very well.</p>
]]></description><link>https://forum.netgate.com/post/957802</link><guid isPermaLink="true">https://forum.netgate.com/post/957802</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 19 Jan 2021 14:08:44 GMT</pubDate></item><item><title><![CDATA[Reply to Just a quick question about BIND on Tue, 19 Jan 2021 12:07:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a> Thank you</p>
<p dir="auto">I hope someone else can help me setup BIND the right way this time (Last time was disaster) My network grown a lot and I am forced to learn how to properly setup DNS to bring back order to my network</p>
<p dir="auto">Small pieces at the time will give me some bases, after that I will take care of the rest. It is not hard, but DNS have so many options that are confusing me</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.netgate.com/post/957786</link><guid isPermaLink="true">https://forum.netgate.com/post/957786</guid><dc:creator><![CDATA[xlameee]]></dc:creator><pubDate>Tue, 19 Jan 2021 12:07:53 GMT</pubDate></item><item><title><![CDATA[Reply to Just a quick question about BIND on Mon, 18 Jan 2021 12:37:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xlameee">@<bdi>xlameee</bdi></a></p>
<p dir="auto">Sorry, can't tell.<br />
I use bind a lot, but not with pfSense.<br />
I edit the bind file config files manually, during setup. After that, they don't need any modification any more - except when I remove or add a domain name..<br />
I'm using bind as the domain name server(s) for my domains. And as a local resolver for the server it's running on.</p>
]]></description><link>https://forum.netgate.com/post/957602</link><guid isPermaLink="true">https://forum.netgate.com/post/957602</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 18 Jan 2021 12:37:02 GMT</pubDate></item><item><title><![CDATA[Reply to Just a quick question about BIND on Mon, 18 Jan 2021 12:16:47 GMT]]></title><description><![CDATA[<p dir="auto">One more question</p>
<p dir="auto">I installed BIND package on my downstream pfsense but I will install on my primary pfsense where all traffic is going to the internet, but first I need to test it to handle my downstream networks</p>
<p dir="auto">So...</p>
<p dir="auto">I set in the Settings to listen on: all vlans, but there is an option on the bottom<br />
"Forwarder Configuration" should I set this "Forwarder IPs" to my upstream resolver or, if this option is not enabled it will simply look what DNS Servers set on System/General Settings ????</p>
<p dir="auto">and....</p>
<p dir="auto">In "Views" I have created and called "localview" where</p>
<p dir="auto">Recursion - Yes<br />
match-clients - Any<br />
but...<br />
allow-recursion - currently set to ANY, but this will be used for local zones isn't more secure to be set to "localnets" then "any" no matter if that is my downstream or upstream pfsense</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.netgate.com/post/957601</link><guid isPermaLink="true">https://forum.netgate.com/post/957601</guid><dc:creator><![CDATA[xlameee]]></dc:creator><pubDate>Mon, 18 Jan 2021 12:16:47 GMT</pubDate></item><item><title><![CDATA[Reply to Just a quick question about BIND on Mon, 18 Jan 2021 11:44:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a> Thank you</p>
]]></description><link>https://forum.netgate.com/post/957598</link><guid isPermaLink="true">https://forum.netgate.com/post/957598</guid><dc:creator><![CDATA[xlameee]]></dc:creator><pubDate>Mon, 18 Jan 2021 11:44:18 GMT</pubDate></item><item><title><![CDATA[Reply to Just a quick question about BIND on Mon, 18 Jan 2021 08:28:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xlameee">@<bdi>xlameee</bdi></a> said in <a href="/post/957570">Just a quick question about BIND</a>:</p>
<blockquote>
<p dir="auto">What are BIND Built-in ACL</p>
</blockquote>
<p dir="auto">https://www.zytrax.com/books/dns/ch7/acl.html</p>
<p dir="auto">So I tend to say : "localhost" if you didn't make your own / if there isn't already a defined :</p>
<pre><code>acl acl-name { 
    address_match_list 
};
</code></pre>
<p dir="auto">which matches other DNS solutions like unbound and dnsmasq.</p>
]]></description><link>https://forum.netgate.com/post/957575</link><guid isPermaLink="true">https://forum.netgate.com/post/957575</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 18 Jan 2021 08:28:29 GMT</pubDate></item></channel></rss>