how run DNS server ?

You could be proper – I am undecided concerning the following so I stand able to be corrected (having restricted expertise of operating a DNS server).Nevertheless, firstly it isn’t clear to me what modifications might be made to the DNS and whether or not they’ll be authoratitive or not. The OP clearly needs to switch some DNS outcomes, however how will that clear up their downside, and for whom? It is potential {that a} easy entry in a “hosts” file could be sufficient. It is also not unusual to have authoratitive DNS data on a webserver (although I keep away from this myself).Secondly, it isn’t clear to me that the dimensions restrict can solely be encountered by authoritative servers in any case – I consider it may be triggered by IPv6 data in addition to DNSSEC and zone switch queries.Thirdly, though I settle for that the intention is for the firewall to not intervene with needed visitors, it isn’t clear to me that limiting the IP addresses that may talk with port 53 might be freed from issues (as a result of distributed nature of DNS), and DNS issues are sufficient of a PITA to diagnose already.I am not saying do not do it, I am simply saying pay attention to the potential penalties and their intermittent nature, which makes testing tough.

