Comment 9 for bug 1774206

Revision history for this message
Andres Rodriguez (andreserl) wrote : Re: MAAS denies recursive DNS queries from subnets it doesn't know about

From the same client that's on a subnet not owned by MAAS:

root@xenial:~# dig @192.168.1.13 api.jujucharms.com

; <<>> DiG 9.10.3-P4-Ubuntu <<>> @192.168.1.13 api.jujucharms.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 7870
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 13, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;api.jujucharms.com. IN A

;; ANSWER SECTION:
api.jujucharms.com. 519 IN A 162.213.33.121

;; AUTHORITY SECTION:
com. 172028 IN NS e.gtld-servers.net.
com. 172028 IN NS k.gtld-servers.net.
com. 172028 IN NS f.gtld-servers.net.
com. 172028 IN NS c.gtld-servers.net.
com. 172028 IN NS b.gtld-servers.net.
com. 172028 IN NS l.gtld-servers.net.
com. 172028 IN NS h.gtld-servers.net.
com. 172028 IN NS j.gtld-servers.net.
com. 172028 IN NS d.gtld-servers.net.
com. 172028 IN NS i.gtld-servers.net.
com. 172028 IN NS g.gtld-servers.net.
com. 172028 IN NS a.gtld-servers.net.
com. 172028 IN NS m.gtld-servers.net.

;; Query time: 4 msec
;; SERVER: 192.168.1.13#53(192.168.1.13)
;; WHEN: Wed May 30 17:17:33 UTC 2018
;; MSG SIZE rcvd: 287

root@xenial:~# nslookup api.jujucharms.com
Server: 192.168.1.13
Address: 192.168.1.13#53

Non-authoritative answer:
Name: api.jujucharms.com
Address: 162.213.33.121