Jump to:navigation, search
Wiki





notempty
Dieser Artikel bezieht sich auf eine nicht mehr aktuelle Version!

notempty
Der Artikel für die neueste Version steht hier

notempty
Zu diesem Artikel gibt es bereits eine neuere Version, die sich allerdings auf eine Reseller-Preview bezieht







































De.png
En.png
Fr.png






General settings for the name server
Last adaptation to the version: 12.2.3
New:
  • EDNS can be disabled for individual servers
  • The sources for DNS queries can be narrowed down
notempty
This article refers to a Resellerpreview

11.8.2


The general settings are made under → Applications →NameserverTab General

Caption Value Description UMV v12.2.3 Nameserver Allgemein-en.png
Tab General
DNSSEC validation in resolver: Off
Warning: If the DNSSEC check is used in conjunction with forward zones, the domains to the zones must be validable in the global DNS. Replies to domains not registered globally will be rejected. This leads to SERVFAIL being used to answer queries about this domain.

When this function is activated, all DNS entries are resolved with DNSSEC without exception. This would also attempt a validation in the DNS hierarchy for only local addresses. However, due to the lack of uniqueness of the local address, it cannot be registered with higher-level DNS servers. An error message appears, the address is not resolved and the zone is therefore not accessible (using DNS).
This applies, for example, to .local domains!

Allow DNS queries only from routed and VPN networks: On
Default
By default, only DNS queries from the following sources are answered:
  • localhost
  • local networks
  • Networks that are routed via another gateway but do not contain a default route (or shared default route)
  • VPN transfer networks or Roadwarrior address pools
Off If DNS queries are to be answered from other external networks as well, this option must be disabled
Disable EDNS for the following servers:    

EDNS can be disabled for servers that do not comply with RFC 6891.

Old or misconfigured name servers sometimes do not use or do not correctly use Extended DNS and as a result do not accept DNS queries that use these protocol extensions.

  • EDNS is mandatory for DNSSEC
    The DO flag (DNSSEC OK) can no longer be placed in the standard header