Accept recursive queeries from these networks only?
What is the correct terminology to identify your network in dns section accept recursive queeries from these networks only? if i put in my domain name it seems to stop all service to my NAT
and am i right in thinking this would block any other users outside of that range from using my dns?
That depends on how literal you take that statement
'using'? no - anyone can use your DNS server if the can get to it - this means that your server can by used by anyone on your LAN, plus anyone outside your network if you have port forwarding setup to provide external access to your server.
What it does control is how the server responds to their requests.
If the client is in the 192.168.1.0/25 range then the server will do its best to resolve the query, including querying upstream servers to find the answer.
Clients outside that network range would only get results for zones that this server is authoritative for. Any other request (e.g. for addresses outside of your domain) would be rejected.
So the upshot is that setting that network range will allow those clients to resolve apple.com addresses, google.com addresses, etc. while everyone else will be limited to the server's own zones.
Similar Messages
-
Have to add 0.0.0.0/0 to "Accept SMTP relays only from these"?
To reach the server via vpn I had to add a virtual IP (192.168.1.1) to the ethernet port. Since then mail acts a bit strange: I have to add 0.0.0.0/0 to "Accept SMTP relays only from these" in SA. Otherwise i get a "[/var/imap/socket/lmtp]: Connection refused" in the smtp log and the server does not accept any delivery of mails from the internets.
I'm not quite sure if it's a good idea. Can anyone please tell if this is still a security risk (while having access restrictions on the mail service)?After a few telnet tests I can answer my own question: It makes an open relay server to spammers! But to solve the former issue with the connection refuse, I had to switch to virtual hosting in the advanced tab of the mail service and add my own domains.
-
I need help. Can LiveCycle PDF Generator accept network print jobs from a PCL only source?
More information about this game:
The game should generate a random obstacle course for the player. The first column of the grid, however, should consist of all empty pieces, with the exception of the upper left-hand corner, which is the grid location where the player initially resides.
Enter a loop in which the following things happen (not necessarily in this order):
Print the current board configuration. Additionally, a key should be printed describing what each piece is.
Get an action from the user. The player can move up, down, left, or right. Use the following controls: up = 'i', down = 'm', left = 'j', right = 'k'. The player can move at most one block at a time. Of course, if the player tries to move into a spot occupied by an immovable block, the player will not move.
Inform the player whether they have won, or if they have lost (a player loses if they step on a bomb piece).
If the player types 'q', the game should terminate.
I am still stuck on this maze generator stuff.... Please help me.... -
I have recently got a Time Capsule with my Macbook pro retina 15". I am trying to setup my time capsule as a wifi station at my home. But the thing is I can only access wifi from my lap only.
How can I share my network from timecapsule to other devices, and im using OS X 10.8.2
Please help me!
Thanks in advance!
(sorry for the bad english)How is the TC currently connected into the network?
It should work fine in bridge and create a wireless network.. it should already be able to share the network without being the main router.
Setting up wireless from wireless is difficult.
I would recommend you buy the USB to ethernet cable Apple sell as an accessory for Air and MBPr so you can actually use ethernet when required. -
Steps to reproduce bug:
1. edit .pdf file from MS network (i.e a share).
1.1 Browsing the network.
1.2 Once that the file is found.
1.3 Select the file, right click and select edit with Adobe Acrobat".
2. save changes.
Results:
I get message box "document could not save because write access was not granted. only read"
Expected results: I have to save the file because the user has all rights file’s security.
Can you help me ?
Thanks in advance
EnricoFirst, you should ask in Acrobat
The Cloud forum is not about using individual programs
The Cloud forum is about the Cloud as a delivery & install process
If you will start at the Forums Index https://forums.adobe.com/welcome
You will be able to select a forum for the specific Adobe product(s) you use
Click the "down arrow" symbol on the right (where it says All communities) to open the drop down list and scroll
Second, different program, but what helps with SOME permission errors is in the link below
Run as Administrator http://forums.adobe.com/thread/969395 (Encore + "All" Premiere) -
HI,
We are getting following error message for all users while sending mail to external but we able to receive mail from internet.
Your message wasn't delivered due to a permission or security issue. It may have been rejected by a moderator, the address may only accept e-mail from certain senders, or another restriction may
be preventing delivery.Hi,
Please follow Luke and Shelly’s suggestion to check your SPF record and Send Connector configuration. Also you can post the complete NDR message(with NDR status code) here for further analysis.
If there is any updates, please feel free to let us know.
Thanks,
Winnie Liang
TechNet Community Support -
Can i get the time capsule to automatically back up my file from my Mac Book Air but have certain files which are only stored on the time capsule and not the computer? Then can i access these files only on the time capsule without connecting it?
igonneau wrote:
Can i get the time capsule to automatically back up my file from my Mac Book Air but have certain files which are only stored on the time capsule and not the computer?
You can, but how are you going to back up those other files? When (not if) your Time Capsule fails, you risk losing them. See #Q3 in Using Time Machine with a Time Capsule for details.
Then can i access these files only on the time capsule without connecting it?
Not sure what you mean. You have to connect a computer, either via Ethernet cable or wirelessly, to read or write to the disk. -
How do I set my computer to accept wireless instructions from only my computer?
How do I set my computer to accept wireless instructions from only my computer?
Please provide the following relevant information so someone can help including:
Printer Model -
Detailed Problem Description -
Operating System of computer (including service pack revision) -
Connection Method - USB, Hardwired LAN, Wireless? -
Make and model of router and modem? -
Error messages - on printer screen and/or computer, any blinking light patterns.
If wireless, status of Blue Wireless light on printer, on, off or blinking? -
Say thanks by clicking the Kudos Thumbs Up to the right in the post.
If my post resolved your problem, please mark it as an Accepted Solution ...
I worked for HP but now I'm retired! -
Oracle VM 3 - only one virtual host accessible from the network (DELL R410)
Hi,
I have installed Oracle VM 3.0.3 and created the network for Virtual hosts. After installing two systems on the server only one is accessible from the network at a time. The second one is not.
Have no idea how e to enable the second host to reach a network.
Maby You have some idea?
Thanks,
JarekHello!!
I'm not an expert but /OVS/Pool should be the directory naming of OVM 2.x, replaced by /OVS/Repositories/REPOS_ID in OVM 3.x
The "wierd directory name" it's the unique ID that OVM assigns to Repository, infact if you go to VM Manager in Repository tab and edit your current repository you will see this ID: 0004fb0000030000839f2d2faa5014c3
Under "0004fb0000030000839f2d2faa5014c3" folder, as you noticed, there are the classic folders ISO, VirtualDisk, VirtualMachine, etc. where files are placed.
I've never tried to import a pre-packaged template from Oracle but I would try importing it as an assembly from http/ftp! ;)
Hope this helps.
Greets! -
Iphone 4 only receiving sms from certain networks- help?!!!!
Iphone 4 is only receiving sms from certain networks - help?!!!
Have you contacted your carrier to report the problem? This is not (and can not be) a problem with the phone. It's a problem with your carrier and/or the way they have your service provisioned.
-
Error Message When Importing Bookmarks From A Network Share
An error message is generated whenever I try to import bookmarks.html from a network share on kubuntu. This same operation is sucessful on the windows version of firefox.
To replicate:
The bookmarks.html is created by Firefox 3.68 on windows 7. And is saved to a network share location. When trying to import this file into firefox 3.6.8 on my kubuntu 10.04 machine, I get the error message/window titled: remote files not accepted. The message states: You can only select local files.
If I copy bookmarks.html local to the kubuntu machine, it imports without error.
On windows, I can import bookmarks.html from the network share without error.
Does anyone know why I can't import across the network on the kubuntu version?
browser being run on windows 7:
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
browser being run on kubuntu 10.04:
Firefox 3.6.8 Mozilla Firefox for Ubuntu canonical - 1.0.It appears to be any remote file, not just the bookmarks file. When trying to upload a file to a website, firefox threw up the same error:
error message/window titled: remote files not accepted. The message states: You can only select local files.
So what is it about files that are sitting on a server, firefox and kubuntu that causes this? I don't get the error message when using win7 on the same files. -
OK, so I'm clearly a newb. I thought if I asked a question, it would post, and now I'm being told to post a comment, so I'm asking the same question again. Sorry I sound like an idiot. I'm new to this apple/mac stuff.
Why does iTunes/iPhone 4S insist it can't find a song on my PC or my phone when it is on both? This is resulting in me being unable to use the ringtones I created from these songs, but I can still play the songs.If you have added the ringtone file correctly to iTunes, it will appear under iTunes 'Tones' library.
If you don't find Tones library in iTunes, go to iTunes menu EDIT/PRFERENCES under GENERAL tab, check the Tones Box under Library source to display Tones library in iTunes.
iTunes accepts only m4r file as ringtone and has to be less than 40secs. -
Monitoring Exchange 2010 from external network
I would like to monitoring the following services pf Exchange 2010 from external network / internet
1) SMTP (To confirm the mail has been accepted for delivery)
2) ActiveSynch (Mobile device can login and synch different folders)
3) WebApp (Users can log and access mail)
I have created a script using test-Mailflow, test-activesynchconnectivity and Test-WebServicesConnectivity and running it on server from LAN. I want to monitor the above 3 areas from Internet(external network) to make sure these services are available
from Internet.
We have Barracuda as SMTP gateway, TMG for WebApp and MobileIron for ActiveSynch.
Will i be able to monitor these services from external network(internet) using test commands. What are the alternate ways to monitor the above services from external network.
ThanksWe are trying to build exactly similar to ExRCA. ExRCA is good but it is manual. We would like to build something similar to ExRCA which can monitor exchange services periodically and send alerts.
-
13017 Received TACACS+ packet from unknown Network Device or AAA Client
I am adding new routers to our Corporate network for a new MPLS network. I am getting 13017 Received TACACS+ packet from unknown Network Device or AAA Client errors for these new routers. They are added to ACS 5.4.0.30 correctly just like all of our other devices. We have never had real routers on the network before, just switches and access points. Is there something special I need to set in ACS for these to work and authenticate correctly? I can only access the currently with built in login locally.
One of the new router configs
Current configuration : 2370 bytes
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname T666
boot-start-marker
boot-end-marker
enable secret 5 $1$h7b3$.T2idTKb9H98BQ8Op0MAC/
aaa new-model
aaa authentication login default group tacacs+ local
aaa authentication enable default group tacacs+ enable
aaa authorization exec default group tacacs+ local if-authenticated
aaa accounting exec default start-stop group tacacs+
aaa session-id common
clock timezone CST -6
clock summer-time CDT recurring
ip cef
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
voice-card 0
crypto pki trustpoint TP-self-signed-2699490457
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2699490457
revocation-check none
rsakeypair TP-self-signed-2699490457
username netadmin privilege 15 secret 5 $1$SIR2$A3MpShVNeAOlTPyLZESr..
interface FastEthernet0/0
ip address 10.114.2.1 255.255.255.0
ip helper-address 10.30.101.4
duplex auto
speed auto
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
interface Serial0/1/0
ip address X.X.X.X 255.255.255.252
no fair-queue
service-module t1 timeslots 1-24
service-module t1 remote-alarm-enable
service-module t1 fdl ansi
no cdp enable
router bgp 65065
no synchronization
bgp log-neighbor-changes
network 10.114.2.0 mask 255.255.255.0
neighbor X.X.X.X remote-as 209
neighbor X.X.X.X default-originate
default-information originate
no auto-summary
ip forward-protocol nd
ip bgp-community new-format
ip http server
ip http authentication aaa
ip http secure-server
ip tacacs source-interface FastEthernet0/0
no logging trap
tacacs-server host 10.30.101.221 key 7 1429005B5C502225
tacacs-server host 10.30.101.222 key 7 1429005B5C502225
tacacs-server directed-request
control-plane
banner exec ^CC
C
Login OK
^C
banner motd ^CC
C
** UNAUTHORIZED ACCESS TO THIS SYSTEM IS PROHIBITED. USE OF
** THIS SYSTEM CONSTITUES CONSENT TO MONITORING AT ALL TIMES.
** RUAN Transport Corporation
** Network Services
** [email protected]
** 515.245.2512
^C
line con 0
line aux 0
line vty 0 4
exec-timeout 30 0
transport input all
line vty 5 15
exec-timeout 30 0
scheduler allocate 20000 1000
end
T666#AAA Protocol > TACACS+ Authentication Details
Date :
September 19, 2014
Generated on September 19, 2014 10:21:27 AM CDT
Authentication Details
Status:
Failed
Failure Reason:
13017 Received TACACS+ packet from unknown Network Device or AAA Client
Logged At:
Sep 19, 2014 10:21 AM
ACS Time:
Sep 19, 2014 10:21 AM
ACS Instance:
acs01
Authentication Method:
Authentication Type:
Privilege Level:
User
Username:
Remote Address:
Network Device
Network Device:
Network Device IP Address:
10.114.2.1
Network Device Groups:
Access Policy
Access Service:
Identity Store:
Selected Shell Profile:
Active Directory Domain:
Identity Group:
Access Service Selection Matched Rule :
Identity Policy Matched Rule:
Selected Identity Stores:
Query Identity Stores:
Selected Query Identity Stores:
Group Mapping Policy Matched Rule:
Authorization Policy Matched Rule:
Authorization Exception Policy Matched Rule:
Other
ACS Session ID:
Service:
AV Pairs:
Response Time:
Other Attributes:
ACSVersion=acs-5.3.0.40-B.839
ConfigVersionId=359
Device Port=59840
Protocol=Tacacs
Authentication Result
Steps
Received TACACS+ packet from unknown Network Device or AAA Client
Additional Details
DiagnosticsACS Configuration Changes -
Uninstalling Flash Player 10 from school networked computers
I am employed by several Primary Schools to support their PC fleets. Both schools have older technology - the one with the problem is running (mainly) Windows XP Pro SP3, with Windows Server 2003 as the server software.
I am the latest of a long line of technicians in these schools and the communal wisdom is that upgrading Flash Player has been an issue foir some time.
Here's the scenario. At some time in the past, the Flash Player 10 Install MSI file was used to populate the PCs with that version of Flash Player. Since that time, a string of technicians have rolled out updates on an individual basis - ignoring the .MSI file sitting in the Group Policy. At some time, someone has actually removed the .msi file, so that the automatic update no longer works, and manual uninstall no longer works either (can't find the install file)!
We need to install Flash Player 11 (for use with several educational web packages), and manual installation only installs the package for the network (or PC) user who is currently logged in to a particular PC.
I've reinstated the Group Policy using the latest Flash Player installation .msi for Windows. I can see that it is installing when I start the PC, but IE STILL uses the older version (10.0, I think), and the web pages in question ask me to install a later version.
Now, I've noticed that there are several hundred sets of user files on each PC, as there is no mechanism to delete these once a login session has completed. I've noticed that there are bits and pieces of Flash Player in many of these, going back at least as far as version 8!
The crux of my problem is What do I have to do to get Flash Player 11 working on these networked PCs? Do I have to remove all those domain user leftover files? And if so, does anyone know how that can be done from a central location (not 1 by 1 as I am reduced to now!)?The first thing I would like to point you to is the Flash Player Admin Guide at http://www.adobe.com/devnet/flashplayer/articles/flash_player_admin_guide.html
You obviously have already found the installer MSI files at http://www.adobe.com/products/flashplayer/distribution3.html - note that the first set are the 64-bit installers, followed by the 32-bit installers.
Basically these installers should remove all older FP versions, but if they don't, try using the uninstaller from http://kb2.adobe.com/cps/141/tn_14157.html
However, I am not sure if you can run the uninstaller via Group Policy; maybe you can find some information on that in the Admin Guide? If not, feel free to ask again; there are some more knowledgeable people than me around here.
Maybe you are looking for
-
Not able to see Data in Xcelsius 2008
Hi everyone, My question is I am not able to see data in Xcelsius spreadsheet although I am able to connect to SAP BW and also able to see and select query but when I select Cross Tab Data in output Values it is not displaying in Xcelsius spreadsheet
-
So you call up an account in email Account Information is selecgted in the 3-choice menu-bar/button (what is that thing called, anyway? An "inspector"? (frown). Then check "enable this account"--is selectable Then Account type: iCloud IMAP or example
-
Multiple text boxes in captivate 5
I have several text boxes in a powerpoint slide in captivate 5. I would like for users to be able to fill in these text boxes in any order. I was able to do this in version 4, but in version 5, it only allows users to respond in the order of the text
-
How to Apply Databank for 2 or more than 2 fields?
hi, Suppose on a form we have 2 fields like First name and Last name . So in .csv file I have given like First Name,Last Name (comma separated) and my databank file gets created. But before playing back the application , how can i attach the databank
-
Deploy Swing Java DB application in Jdeveloper 11g
Hi I created a simple Swing Java DB application in Jdeveloper 11g, after I deploy this simple swing application, I try to run the jar file, I got the following error: C:\Jdev1013\jdevhome\jdev\mywork\Application2\Client\deploy>java -jar myJar.jar Exc