summaryrefslogtreecommitdiff
path: root/docs
diff options
context:
space:
mode:
authorchariri <w@chariri.moe>2026-09-11 23:52:08 +0900
committerGitHub <noreply@github.com>2026-09-11 15:52:08 +0100
commitd09abd509c9b9a822c8f90b1c92168d01acf49a4 (patch)
treee0997c801d950e6cb7f5415ab4dff6bf9dd0780e /docs
parentd9533ece67ade759103bdd9f6fc3b0b95c17c4da (diff)
downloadvyos-documentation-d09abd509c9b9a822c8f90b1c92168d01acf49a4.tar.gz
vyos-documentation-d09abd509c9b9a822c8f90b1c92168d01acf49a4.zip
docs: T8045: document dont-query (#2211)
* docs: T8045: document dont-query --------- Co-authored-by: Daniil Baturin <daniil@baturin.org>
Diffstat (limited to 'docs')
-rw-r--r--docs/configuration/service/dns.md22
1 files changed, 22 insertions, 0 deletions
diff --git a/docs/configuration/service/dns.md b/docs/configuration/service/dns.md
index 8e98a43a..a18e47e6 100644
--- a/docs/configuration/service/dns.md
+++ b/docs/configuration/service/dns.md
@@ -180,6 +180,28 @@ set service dns forwarding source-address 192.0.2.1
set service dns forwarding source-address 2001:db8::1
```
+```{cfgcmd} set service dns forwarding dont-query \<address | prefix\>
+
+**Add an IPv4 or IPv6 address or prefix to the recursor's exclusion list
+of servers to query.**
+
+Prefix a value with `!` to make it an exception to that list.
+
+The recursor selects the most specific matching prefix. When positive and
+negative entries use the same prefix, the entry configured last takes
+precedence.
+
+The list applies to addresses discovered during recursive resolution
+(e.g., NS records).
+The recursor still sends queries to explicitly configured upstream DNS servers.
+```
+
+Example:
+
+```none
+set service dns forwarding dont-query !127.0.0.0/8
+```
+
```{cfgcmd} set service dns forwarding no-serve-rfc1918
**Disable authoritative answering of queries for `10.in-addr.arpa`,