ISC/Spamhaus Webinar: It's Time to Try a DNS Firewall, 14 December 2017

Опубликовано: 02 Май 2026
на канале: Internet Systems Consortium
572
5

Internet Systems Consortium (ISC) is presenting a webinar with guest Matt Stith, Product Manager at Spamhaus/Deteque on using Response Policy Zones to establish a DNS Firewall.

If you run BIND, you have probably heard of RPZ. It is no longer a ‘bleeding edge’ feature: it is now considered a best practice. Would you run a mailserver without a spam filter? Of course not, and you should seriously consider a filter on your DNS as well, for the same reasons.

Response Policy Zones were invented to provide filtering for abuse. Every supported version of BIND includes RPZ, and the new BIND 9.12 version includes a completely re-written improved implementation. ISC invested in re-factoring RPZ support because we think it is a critical feature.

This webinar includes an invited guest from Spamhaus-Deteque who will present a real life case study demonstrating how RPZ has helped a well-known hosting provider identify and DROP over 200 million abuse queries in a few days. We’ll discuss how to quickly trial DNS RPZ on your own servers, including access to (free) RPZ zones so you can test drive this exciting feature.

What is DNS RPZ?

Threat Intelligence on known malicious sites (malware, ransomware, bots, etc) is packaged into data zones that are consumed by a DNS resolver to block access to known malicious sources on the internet. Fast, timely updates (every 1 minute) enable an advanced layer of protection for all users, all applications, and all protocols. By subscribing to an RPZ data feed from a security provider, you can block both incoming and outgoing malicious sources from entering a network via DNS responses.

The slides from this presentation are available at: https://www.isc.org/docs/RPZ-webinar7....

You are welcome to post your questions about BIND 9 DNS on our helpful community mailing list at https://lists.isc.org/mailman/listinf.... The BIND Administrative Reference Manual is online at https://bind9.readthedocs.io/en/stable/. We also maintain a knowledgebase of handy technical articles at https://kb.isc.org.

Internet Systems Consortium maintains and publishes the BIND 9 DNS software under the open source MPL 2.0 license. ISC is a non-profit, operating to help support the Internet infrastructure and facilitate independent connection to and participation in the Internet. We support this work by offering users professional technical support contracts, including advance notification of security vulnerabilities before public disclosure.

---
Learn more at https://www.isc.org or https://www.dnsrpz.info