Bind
Overview
If you are using Bind as your internal DNS server and want to forward all incoming requests to our cloud servers, you can easily enable our malware protection and content filtering features. Please follow the steps below to configure the forwarding rules. For more information on how Bind works, you can visit their official website.
Before proceeding with this guide, you must register your public IP address in your dashboard. Only registered IP addresses can use the malware protection and content filtering features on their network. You can do this by navigating to your control panel and accessing the Networks section.
Configuration Steps
Locate the Configuration Folder
Move to the directory that contains the Bind configuration files. By default, the folder should be located at the following path:
cd /etc/bindOpen the Options File
The file we need to change is the named.conf.options file. Open it in your preferred text editor with sudo privileges:
sudo nano named.conf.optionsAdd the Forwarders Block
Within the options block, we need to create another section called forwarders. This new block will contain the IP addresses of the DNS servers to which we want to forward all requests. You must enter our primary and secondary IPs.
Set the Forward Directive
Now we need to set the forward directive to the value "only" right below the forwarders block. This ensures your server will automatically forward all requests and will not attempt to resolve them on its own.
When finished, your configuration file should look exactly like this:
options {
directory "/var/cache/bind";
forwarders {
185.236.104.104;
185.236.105.105;
};
forward only;
dnssec-validation auto;
auth-nxdomain no; # conform to RFC1035
listen-on-v6 { any; };
};Verify the Syntax
Save and close the file once you are done. To check if you have done everything correctly, you can use the built-in tools provided by Bind to verify the syntax of the configuration files. Simply type the following command in your terminal:
sudo named-checkconfIf there are no syntax errors in your configuration, the shell prompt will terminate immediately without displaying any output.
Restart the Service
Finally, you need to restart the Bind daemon to implement the new changes. You can do this with the following command. Note that the command below uses Bind 9. Please replace the service name with the specific version you are currently using if it is different.
sudo service bind9 restartWe are done! You should now have your Bind server properly configured to start filtering content and protecting your network from malware.