I have this working, but just to clarify...
Any lines in /var/log/messages, along the lines of...
lame server resolving 'xxx.com' (in 'xxx.com'?): 11.22.33.44
...are the result of attempts to recursively query cached dns, and the only way I can currently handle it is to add these IPs to a black-hole ACL?
The reason I ask is because in the last 3 days or so, I have roughly 2,800 of these entries originating from about 250 unique IPs. This could be quite a PIA to keep up with, and I'm unsure if I would be black-holing anything legitimate.
TIA for any thoughts,
verdon
Any lines in /var/log/messages, along the lines of...
lame server resolving 'xxx.com' (in 'xxx.com'?): 11.22.33.44
...are the result of attempts to recursively query cached dns, and the only way I can currently handle it is to add these IPs to a black-hole ACL?
The reason I ask is because in the last 3 days or so, I have roughly 2,800 of these entries originating from about 250 unique IPs. This could be quite a PIA to keep up with, and I'm unsure if I would be black-holing anything legitimate.
TIA for any thoughts,
verdon