1
0
Fork 0
mirror of https://github.com/roles-ansible/ansible_role_unbound.git synced 2024-08-16 13:39:49 +02:00
ansible_role_unbound/files/snippets/private-addresses.conf
2018-03-10 19:18:04 +01:00

31 lines
965 B
Text

server:
# Give IPv4 of IPv6 addresses or classless subnets. These are addresses on your private network,
# and are not allowed to be returned for public internet names. Any occurrence of such addresses
# are removed from DNS answers. Additionally, the DNSSEC validator may mark the answers bogus.
# This protects against so-called DNS Rebinding.
# localhost
private-address: 127.0.0.0/8
# private IPv4 address spaces (rfc 1918)
private-address: 10.0.0.0/8
private-address: 172.16.0.0/12
private-address: 192.168.0.0/16
# carrier-grade NAT (rfc 6598)
private-address: 100.64.0.0/10
# link-local addresses
private-address: 169.254.0.0/16
# localhost
private-address: ::/128
# unique local addresses (rfc 4193)
private-address: fd00::/8
# link-local addresses (rfc 4862, 4291)
private-address: fe80::/10
# IPv4-mapped addresses (rfc 4291)
private-address: ::ffff:0:0/96