Looks like the move to using RPZ in BIND went smoothly and things are working as intended.
Author: Adrian Alexdre (FurrIX, Network Operations Center)
I am in the process of moving our two name servers from using IPtables for malicious domain blocking to using RPZs within BIND. If this works as I intend, it should cut back on the amount of upkeep involved in blocking known, high volume C&C lookups; making us quicker to update and add new domains to the list. Also, domains on this list will return NXDOMAIN.
I am happy to announce that both Marbled Fennec Networks and FurrIX have a full team of volunteers once again. We should be able to begin bringing the network back into an up to date state along with offering a broader range of services once the new team members are brought up to speed.
As it sits now, we have eight members working together to keep MFN and FurrIX operational. Feel free to take a look at our team page to see who all is volunteering and what parts of our projects they support!
I finally got a moment to check on what was going on with the secondary physical server and it appears something triggered some kind of bug in which the network interface started resetting randomly and would come back up at 100Mbps before dying again.
I don’t see an actual reason for this in the system logs, which is very puzzling…but after a system reboot and sending a tech to look at the server’s networking cable just to be sure- it appears the box is running okay again.
This means that we will need to keep an eye on this box and make sure we catch on to future possible errors before they take the system out.
