Unbound 1.6.0rc1 prerelease

W.C.A. Wijngaards wouter at nlnetlabs.nl
Thu Dec 15 08:16:13 UTC 2016


Hi Spike,

Just wanted to add a small comment:

On 15/12/16 05:04, Spike via Unbound-users wrote:
> unfortunately in some cases I need inverted regexps/whitelists, for
> example allow sub.domain.tld but otherwise block *.domain.tld. As far as
> I could see you can't do that with local-data.

Yes this is possible, with
local-zone: "domain.tld" static
local-zone: "sub.domain.tld" transparent

The most specific match is used.  The sub.domain.tld resolves normally.
But other queries, like foo.domain.tld, get NXDOMAIN.

Best regards, Wouter

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.nlnetlabs.nl/pipermail/unbound-users/attachments/20161215/6c5778ee/attachment.bin>


More information about the Unbound-users mailing list