we-are-mono / filesystem

The OS foundation for our upcoming router
MIT License
57 stars 2 forks source link

Keep unbound from answering external requests #3

Open peterablehmann opened 2 months ago

peterablehmann commented 2 months ago

This change tells unbound to only listen on the IPv4 address of the LAN (eth1) interface. This will keep it from participating in a DNS amplification attack initiated by an outside attacker. Unbound should only reply to requests coming from one of it's downstream networks.