Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
docker_notes:docker-dhcp [2024-07-21 Sun wk29 12:15] – [DNSSEC] baumkp | docker_notes:docker-dhcp [2024-08-31 Sat wk35 17:35] (current) – [DHCP testing] baumkp | ||
---|---|---|---|
Line 36: | Line 36: | ||
====DHCP testing==== | ====DHCP testing==== | ||
- | '' | + | '' |
===Reference=== | ===Reference=== | ||
Line 76: | Line 77: | ||
- | =====DNSSEC===== | ||
- | My local DNS server is a recursive caching type only. It take local (LAN) DNS queries and answers directly for any LAN name resolution, checks the cache for any external name resolution and then if not found locally or in cache checks the specified external DNS servers to resolve names. | ||
- | |||
- | For external name resolution Bind9 basically now defaults to automatic use of DNSSEC. | ||
- | *'' | ||
- | *'' | ||
- | |||
- | Equally important the following commands helps confirm that invalid DNS queries have failed and do not rerun invalid IP address, which would be security risk. If '' | ||
- | |||
- | Basic Bind9 DNSSEC configuration options | ||
- | * The option (in ''/ | ||
- | * The option '' | ||
- | |||
- | <fc # | ||
- | |||
- | ====reference==== | ||
- | *[[https:// | ||
- | *[[https:// | ||
- | *[[https:// | ||
- | *[[https:// | ||
- | ++++ old references | | ||
- | *[[https:// | ||
- | *[[https:// | ||
- | ++++ | ||
- | =====DNS over TLS (DoT)===== | ||
=====References===== | =====References===== | ||
*KPTree.net' | *KPTree.net' |