[On 26 Jan, @18:32, Peter Koch wrote in "message ``sendto failed: Inval
..."]> So, nsd could (silently) ignore DNS packets with src port 0 or log the
> error with more detail or both. Opinions?
Hmm... the current behavoir of NSD should be changed IMO. The danger
is that if we log such queries we create a small DOS attack (which is
also present now). So I would like to silently ignore such queries,
maybe only log them when NSD is compiled with --enable-checking.
regards,
--
grtz,
- Miek
http://www.miek.nl http://www.nlnetlabs.nl
PGP: 6A3C F450 6D4E 7C6B C23C F982 258B 85CF 3880 D0F6
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL:
<http://lists.nlnetlabs.nl/pipermail/nsd-users/attachments/20060130/2d76656b/attachment.bin>