[dns-operations] NSEC3PARAM change strange behaviour
Petr Špaček
pspacek at isc.org
Thu Oct 12 11:30:42 UTC 2023
On 12. 10. 23 13:09, Misak Khachatryan wrote:
> Thank you Viktor,
>
> In logs I see IXFR, which should be a case. This brings me to question
> to bind developers - shouldn't a change of dnssec-policy or at least
> such destructive ones automatically trigger AXFR?
>
> Of course it's not a question to be asked here, I will check the
> documentation of bind and ask it in the appropriate mailing list.
Just to close the loop, you can configure "max-ixfr-ratio" option. See
https://bind9.readthedocs.io/en/latest/reference.html#namedconf-statement-max-ixfr-ratio
Please send further questions to mailing list
https://lists.isc.org/mailman/listinfo/bind-users
--
Petr Špaček
Internet Systems Consortium
More information about the dns-operations
mailing list