[dnsdist] dnsdist 1.7 : allow only A request

david.neau at orange.com david.neau at orange.com
Fri Mar 17 15:37:36 UTC 2023

Hi Jacob,

Here :

[root at UAVARRDIJ01 ~]# cat /etc/dnsdist/dnsdist.conf
-- DNSdist configuration file

-- disable security status polling via DNS

-- world reachable
setACL({'', '::/0'})

-- listen on

-- control socket on localhost

-- webserver ("")
setWebserverConfig({password="xxxx", apiKey="xxxxx", acl=""})



cat /etc/dnsdist/conf.d/myconf_dnsdit.conf


newServer({address="", name="my_server", pool="local", qps=1000, order=1, weight=10, useClientSubnet=true})

newServer({address="", name="remote-server" , pool="remote", checkType="A", checkName="my_domain.fr" , qps=1500, order=1, weight=10 , useClientSubnet=true})

NotRule (
OrRule {QTypeRule(DNSQType.A), QTypeRule(DNSQType.AAAA)}

addAction({'toto.com'}, PoolAction("local"))
addAction({'titi.com'}, PoolAction("remote-server"))

Orange Restricted

-----Message d'origine-----
De : dnsdist <dnsdist-bounces at mailman.powerdns.com> De la part de Jacob Bunk Nielsen via dnsdist
Envoyé : vendredi 17 mars 2023 16:27
À : dnsdist at mailman.powerdns.com
Objet : Re: [dnsdist] dnsdist 1.7 : allow only A request


On 17/03/2023 16.23, david.neau at orange.com wrote:
> Hello all
> After some tests I see a potential issue, tell me if I m right please :
> It works for A request :
> [root at node ~]# dig a 
> https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.t
> oto.com%2F&data=05%7C01%7Cdavid.neau%40orange.com%7C3f1a3779819f422afd
> 2308db26fc038f%7C90c7a20af34b40bfbc48b9253b6f5d20%7C0%7C0%7C6381466360
> 48960015%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiL
> CJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=hIHI2hcmF6p5xsmQmL
> pzXS%2BVERe5nietPu20Tn6ILjs%3D&reserved=0 @X.X.X.X +short
> It stays mute more most of the requests ( expected behavior ), ^C is needed to get the prompt back.

Please provide the full configuration of dnsdist in your setup, otherwise it will be close to impossible to help you figure out why things work the way they do.

Best regards,


dnsdist mailing list
dnsdist at mailman.powerdns.com


Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.

More information about the dnsdist mailing list