Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

GSS domain-lists

Hi everyone,

I have a query about GSS devices and domain-lists.

At the moment we have individual domain-lists configured, for example:

domain-list DOMAIN1

domain DOMAIN1.EXAMPLE.COM

domain-list DOMAIN2

domain DOMAIN2.EXAMPLE.COM

domain-list DOMAIN3

domain DOMAIN3.EXAMPLE.COM

We also have a global forward rule to send for any unknown requests to an upstream name-server.

We are seeing an unwanted effect when internal hosts try to resolve unknown domains within *.EXAMPLE.COM. We would like to avoid these requests from being forwarded upstream.

Essentially we need the GSS to return a NXDOMAIN message for anything unknown with *.EXAMPLE.COM.

Thanks,

Paul

1 REPLY
Cisco Employee

Re: GSS domain-lists

you could set up another domain list with .*\.example\.com the use a dns rule without an answer.This woiuld give you a serverfail rather than nxdomain but will keep you from forwarding.

190
Views
0
Helpful
1
Replies