mirror of
https://github.com/NLnetLabs/unbound.git
synced 2025-12-20 23:00:56 -05:00
- For #1102: clearer text for using interface-* options for the
loopback interface.
This commit is contained in:
parent
3adb9c8f92
commit
7083d58c6b
2 changed files with 10 additions and 3 deletions
|
|
@ -1,5 +1,7 @@
|
||||||
12 July 2024: Yorgos
|
12 July 2024: Yorgos
|
||||||
- Add RPZ tag tests in acl_interface.tdir.
|
- Add RPZ tag tests in acl_interface.tdir.
|
||||||
|
- For #1102: clearer text for using interface-* options for the
|
||||||
|
loopback interface.
|
||||||
|
|
||||||
12 July 2024: Wouter
|
12 July 2024: Wouter
|
||||||
- Fix #1103: unbound 1.20.0 segmentation fault with nghttp2.
|
- Fix #1103: unbound 1.20.0 segmentation fault with nghttp2.
|
||||||
|
|
|
||||||
|
|
@ -788,7 +788,8 @@ transports, regardless of the presence of an DNS Cookie and regardless of the
|
||||||
UDP queries without a DNS Cookie receive REFUSED responses with the TC flag set,
|
UDP queries without a DNS Cookie receive REFUSED responses with the TC flag set,
|
||||||
that may trigger fall back to TCP for those clients.
|
that may trigger fall back to TCP for those clients.
|
||||||
.IP
|
.IP
|
||||||
By default only localhost is \fIallow\fRed, the rest is \fIrefuse\fRd.
|
By default only localhost (the 127.0.0.0/8 IP netblock, not the loopback
|
||||||
|
interface) is implicitly \fIallow\fRed, the rest is \fIrefuse\fRd.
|
||||||
The default is \fIrefuse\fRd, because that is protocol\-friendly. The DNS
|
The default is \fIrefuse\fRd, because that is protocol\-friendly. The DNS
|
||||||
protocol is not designed to handle dropped packets due to policy, and
|
protocol is not designed to handle dropped packets due to policy, and
|
||||||
dropping may result in (possibly excessive) retried queries.
|
dropping may result in (possibly excessive) retried queries.
|
||||||
|
|
@ -824,8 +825,12 @@ Similar to \fBaccess\-control:\fR but for interfaces.
|
||||||
.IP
|
.IP
|
||||||
The action is the same as the ones defined under \fBaccess\-control:\fR.
|
The action is the same as the ones defined under \fBaccess\-control:\fR.
|
||||||
Interfaces are \fIrefuse\fRd by default.
|
Interfaces are \fIrefuse\fRd by default.
|
||||||
By default only localhost (the IP netblock, not the loopback interface) is
|
By default only localhost (the 127.0.0.0/8 IP netblock, not the loopback
|
||||||
\fIallow\fRed through the default \fBaccess\-control:\fR behavior.
|
interface) is implicitly \fIallow\fRed through the default
|
||||||
|
\fBaccess\-control:\fR behavior.
|
||||||
|
This also means that any attempt to use the \fBinterface-*:\fR options for the
|
||||||
|
loopback interface will not work as they will be overridden by the implicit
|
||||||
|
default "\fBaccess\-control:\fR 127.0.0.0/8 allow" option.
|
||||||
.IP
|
.IP
|
||||||
Note that the interface needs to be already specified with \fBinterface:\fR
|
Note that the interface needs to be already specified with \fBinterface:\fR
|
||||||
and that any \fBaccess-control*:\fR setting overrides all \fBinterface-*:\fR
|
and that any \fBaccess-control*:\fR setting overrides all \fBinterface-*:\fR
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue