summaryrefslogtreecommitdiff
path: root/examples/bind/named.conf
blob: dbb6158d489c09b99e1b0ceae77c514250fdad4e (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
options {
	directory "/home/jagger/fuzz/bind/dist/etc";
	port 53;
	tcp-clients 100000;
	tcp-listen-queue 1000000;
	recursion yes;
	recursive-clients 1000000;
	max-clients-per-query 100000;
	max-recursion-queries 100000;
	max-recursion-depth 2;
	max-cache-size 1;
	max-acache-size 1;
	acache-enable yes;
	max-ncache-ttl 1;
	max-cache-ttl 1;
	lame-ttl 1;
	reserved-sockets 2048;
	max-retry-time 1;
	max-refresh-time 1;
	check-integrity false;
	cleaning-interval 1;
	notify yes;
	dnssec-enable yes;
	dnssec-validation yes;
	dnssec-secure-to-insecure yes;
	dnssec-lookaside no;
	allow-new-zones yes;
	interface-interval 0;
	additional-from-auth yes;
	additional-from-cache yes;
	minimal-responses no;
	prefetch 1 1;
	resolver-query-timeout 1;
	auth-nxdomain yes;
	empty-server "tesZ";
	disable-empty-zone "tesY";
	zone-statistics yes;
	preferred-glue AAAA;
	query-source 127.0.0.3;
	querylog yes;
	multi-master yes;
	serial-query-rate 10000;
	transfer-format many-answers;
	transfers-per-ns 10000;

	allow-query {
		any;
	};
	allow-query-cache {
		any;
	};
	allow-recursion {
		any;
	};
	allow-transfer {
		any;
	};
	allow-update-forwarding {
		any;
	};

	forward only;

	forwarders {
		127.0.0.2 port 53;
	};

	rate-limit {
		responses-per-second 0;
		all-per-second 0;
		window 1;
		log-only yes;
		exempt-clients {
			127.0.0.0/8;
		};
	};
};

logging {
	channel string {
		file "/tmp/out" size 1M;
		severity debug;
	};
	category default {
		string;
	};
};

zone "test." {
	type master;
	file "test.zone";
	also-notify { 127.0.0.2; };
};

key "rndc-key" {
	algorithm hmac-md5;
	secret "fLiXsUga061TFu7G7Ex5fw==";
};

controls {
	inet 127.0.0.1 port 953
	allow { 127.0.0.1; } keys { "rndc-key"; };
};