options revision 795beed7207cb3501cd3f89cec165c07ad86dee2
0N/A
210N/AThis is a summary of the named.conf options supported by
210N/Athis version of BIND 9.
210N/A
210N/Aacl <string> { <address_match_element>; ... };
210N/A
210N/Acontrols {
210N/A inet ( <ipv4_address> | <ipv6_address> | * ) [ port ( <integer> | *
210N/A ) ] allow { <address_match_element>; ... } [ keys { <string>;
0N/A ... } ];
0N/A unix <quoted_string> perm <integer> owner <integer> group <integer>
0N/A [ keys { <string>; ... } ];
0N/A};
0N/A
0N/Adlz <string> {
0N/A database <string>;
0N/A search <boolean>;
0N/A};
0N/A
0N/Akey <string> {
0N/A algorithm <string>;
0N/A secret <string>;
0N/A};
0N/A
0N/Alogging {
0N/A category <string> { <string>; ... };
0N/A channel <string> {
0N/A buffered <boolean>;
0N/A file <quoted_string> [ versions ( "unlimited" | <integer> )
0N/A ] [ size <size> ];
0N/A null;
0N/A print-category <boolean>;
0N/A print-severity <boolean>;
0N/A print-time <boolean>;
0N/A severity <log_severity>;
0N/A stderr;
0N/A syslog <optional_facility>;
44N/A };
210N/A};
210N/A
210N/Alwres {
210N/A listen-on [ port <integer> ] [ dscp <integer> ] { ( <ipv4_address>
210N/A | <ipv6_address> ) [ port <integer> ] [ dscp <integer> ]; ... };
210N/A lwres-clients <integer>;
210N/A lwres-tasks <integer>;
210N/A ndots <integer>;
210N/A search { <string>; ... };
210N/A view <string> <optional_class>;
210N/A};
210N/A
210N/Amanaged-keys { <string> <string> <integer> <integer> <integer>
210N/A <quoted_string>; ... };
210N/A
210N/Amasters <string> [ port <integer> ] [ dscp <integer> ] { ( <masters> |
210N/A <ipv4_address> [ port <integer> ] | <ipv6_address> [ port <integer> ] )
210N/A [ key <string> ]; ... };
210N/A
210N/Aoptions {
210N/A acache-cleaning-interval <integer>;
210N/A acache-enable <boolean>;
210N/A additional-from-auth <boolean>;
210N/A additional-from-cache <boolean>;
210N/A allow-new-zones <boolean>;
210N/A allow-notify { <address_match_element>; ... };
210N/A allow-query { <address_match_element>; ... };
210N/A allow-query-cache { <address_match_element>; ... };
210N/A allow-query-cache-on { <address_match_element>; ... };
210N/A allow-query-on { <address_match_element>; ... };
210N/A allow-recursion { <address_match_element>; ... };
210N/A allow-recursion-on { <address_match_element>; ... };
210N/A allow-transfer { <address_match_element>; ... };
210N/A allow-update { <address_match_element>; ... };
210N/A allow-update-forwarding { <address_match_element>; ... };
210N/A allow-v6-synthesis { <address_match_element>; ... }; // obsolete
210N/A also-notify [ port <integer> ] [ dscp <integer> ] { ( <masters> |
210N/A <ipv4_address> [ port <integer> ] | <ipv6_address> [ port
210N/A <integer> ] ) [ key <string> ]; ... };
210N/A alt-transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * )
210N/A ] [ dscp <integer> ];
210N/A alt-transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> |
210N/A * ) ] [ dscp <integer> ];
210N/A attach-cache <string>;
210N/A auth-nxdomain <boolean>; // default changed
210N/A auto-dnssec ( allow | maintain | off );
210N/A automatic-interface-scan <boolean>;
210N/A avoid-v4-udp-ports { <portrange>; ... };
210N/A avoid-v6-udp-ports { <portrange>; ... };
210N/A bindkeys-file <quoted_string>;
210N/A blackhole { <address_match_element>; ... };
210N/A cache-file <quoted_string>;
210N/A check-dup-records ( fail | warn | ignore );
210N/A check-integrity <boolean>;
210N/A check-mx ( fail | warn | ignore );
210N/A check-mx-cname ( fail | warn | ignore );
210N/A check-names ( master | slave | response ) ( fail | warn | ignore );
210N/A check-sibling <boolean>;
210N/A check-spf ( warn | ignore );
210N/A check-srv-cname ( fail | warn | ignore );
210N/A check-wildcard <boolean>;
210N/A cleaning-interval <integer>;
210N/A clients-per-query <integer>;
210N/A coresize <size>;
210N/A datasize <size>;
210N/A deallocate-on-exit <boolean>; // obsolete
210N/A deny-answer-addresses { <address_match_element>; ... } [
210N/A except-from { <quoted_string>; ... } ];
210N/A deny-answer-aliases { <quoted_string>; ... } [ except-from {
210N/A <quoted_string>; ... } ];
210N/A dialup <dialuptype>;
210N/A directory <quoted_string>;
210N/A disable-algorithms <string> { <string>; ... };
210N/A disable-ds-digests <string> { <string>; ... };
210N/A disable-empty-zone <string>;
210N/A dns64 <netprefix> {
210N/A break-dnssec <boolean>;
210N/A clients { <address_match_element>; ... };
210N/A exclude { <address_match_element>; ... };
210N/A mapped { <address_match_element>; ... };
210N/A recursive-only <boolean>;
210N/A suffix <ipv6_address>;
210N/A };
210N/A dns64-contact <string>;
210N/A dns64-server <string>;
210N/A dnssec-accept-expired <boolean>;
210N/A dnssec-dnskey-kskonly <boolean>;
210N/A dnssec-enable <boolean>;
210N/A dnssec-loadkeys-interval <integer>;
210N/A dnssec-lookaside ( <string> trust-anchor <string> | auto | no );
210N/A dnssec-must-be-secure <string> <boolean>;
210N/A dnssec-secure-to-insecure <boolean>;
210N/A dnssec-update-mode ( maintain | no-resign );
210N/A dnssec-validation ( yes | no | auto );
210N/A dscp <integer>;
210N/A dual-stack-servers [ port <integer> ] { ( <quoted_string> [ port
210N/A <integer> ] [ dscp <integer> ] | <ipv4_address> [ port
210N/A <integer> ] [ dscp <integer> ] | <ipv6_address> [ port
210N/A <integer> ] [ dscp <integer> ] ); ... };
210N/A dump-file <quoted_string>;
210N/A edns-udp-size <integer>;
210N/A empty-contact <string>;
210N/A empty-server <string>;
210N/A empty-zones-enable <boolean>;
210N/A fake-iquery <boolean>; // obsolete
210N/A fetch-glue <boolean>; // obsolete
210N/A files <size>;
210N/A filter-aaaa { <address_match_element>; ... }; // not configured
210N/A filter-aaaa-on-v4 <filter_aaaa>; // not configured
210N/A filter-aaaa-on-v6 <filter_aaaa>; // not configured
210N/A flush-zones-on-shutdown <boolean>;
210N/A forward ( first | only );
210N/A forwarders [ port <integer> ] [ dscp <integer> ] { ( <ipv4_address>
210N/A | <ipv6_address> ) [ port <integer> ] [ dscp <integer> ]; ... };
210N/A geoip-directory ( <quoted_string> | none ); // not configured
210N/A geoip-use-ecs ( <quoted_string> | none ); // not configured
210N/A has-old-clients <boolean>; // obsolete
210N/A heartbeat-interval <integer>;
210N/A host-statistics <boolean>; // not implemented
210N/A host-statistics-max <integer>; // not implemented
210N/A hostname ( <quoted_string> | none );
210N/A inline-signing <boolean>;
210N/A interface-interval <integer>;
210N/A ixfr-from-differences <ixfrdiff>;
210N/A key-directory <quoted_string>;
210N/A lame-ttl <ttlval>;
210N/A listen-on [ port <integer> ] [ dscp <integer> ] {
210N/A <address_match_element>; ... };
210N/A listen-on-v6 [ port <integer> ] [ dscp <integer> ] {
210N/A <address_match_element>; ... };
210N/A maintain-ixfr-base <boolean>; // obsolete
210N/A managed-keys-directory <quoted_string>;
210N/A masterfile-format ( text | raw | map );
210N/A masterfile-style ( full | relative );
210N/A match-mapped-addresses <boolean>;
210N/A max-acache-size <size_no_default>;
210N/A max-cache-size <size_no_default>;
210N/A max-cache-ttl <integer>;
210N/A max-clients-per-query <integer>;
210N/A max-ixfr-log-size <size>; // obsolete
210N/A max-journal-size <size_no_default>;
210N/A max-ncache-ttl <integer>;
210N/A max-recursion-depth <integer>;
210N/A max-recursion-queries <integer>;
210N/A max-refresh-time <integer>;
210N/A max-retry-time <integer>;
210N/A max-rsa-exponent-size <integer>;
210N/A max-transfer-idle-in <integer>;
210N/A max-transfer-idle-out <integer>;
210N/A max-transfer-time-in <integer>;
210N/A max-transfer-time-out <integer>;
210N/A max-udp-size <integer>;
210N/A max-zone-ttl <maxttl_no_default>;
210N/A memstatistics <boolean>;
210N/A memstatistics-file <quoted_string>;
210N/A min-refresh-time <integer>;
210N/A min-retry-time <integer>;
210N/A min-roots <integer>; // not implemented
210N/A minimal-responses <boolean>;
210N/A multi-master <boolean>;
210N/A multiple-cnames <boolean>; // obsolete
210N/A named-xfer <quoted_string>; // obsolete
210N/A no-case-compress { <address_match_element>; ... };
210N/A nosit-udp-size <integer>; // not configured
210N/A notify <notifytype>;
210N/A notify-delay <integer>;
210N/A notify-rate <integer>;
210N/A notify-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A notify-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * ) ]
210N/A [ dscp <integer> ];
210N/A notify-to-soa <boolean>;
210N/A nsec3-test-zone <boolean>; // test only
210N/A nta-lifetime <ttlval>;
210N/A nta-recheck <ttlval>;
210N/A pid-file ( <quoted_string> | none );
210N/A port <integer>;
210N/A preferred-glue <string>;
210N/A prefetch <integer> [ <integer> ];
210N/A provide-ixfr <boolean>;
259N/A query-source <querysource4>;
259N/A query-source-v6 <querysource6>;
259N/A querylog <boolean>;
259N/A queryport-pool-ports <integer>; // obsolete
259N/A queryport-pool-updateinterval <integer>; // obsolete
259N/A random-device <quoted_string>;
259N/A rate-limit {
259N/A all-per-second <integer>;
259N/A errors-per-second <integer>;
259N/A exempt-clients { <address_match_element>; ... };
210N/A ipv4-prefix-length <integer>;
210N/A ipv6-prefix-length <integer>;
210N/A log-only <boolean>;
210N/A max-table-size <integer>;
210N/A min-table-size <integer>;
210N/A nodata-per-second <integer>;
210N/A nxdomains-per-second <integer>;
210N/A qps-scale <integer>;
210N/A referrals-per-second <integer>;
210N/A responses-per-second <integer>;
210N/A slip <integer>;
210N/A window <integer>;
210N/A };
210N/A recursing-file <quoted_string>;
210N/A recursion <boolean>;
210N/A recursive-clients <integer>;
210N/A request-expire <boolean>;
210N/A request-ixfr <boolean>;
210N/A request-nsid <boolean>;
210N/A request-sit <boolean>; // not configured
210N/A reserved-sockets <integer>;
210N/A resolver-query-timeout <integer>;
210N/A response-policy { zone <quoted_string> [ policy ( given | disabled
210N/A | passthru | no-op | drop | tcp-only | nxdomain | nodata |
210N/A cname <quoted_string> ) ] [ recursive-only <boolean> ] [
210N/A max-policy-ttl <integer> ]; ... } [ recursive-only <boolean> ]
210N/A [ break-dnssec <boolean> ] [ max-policy-ttl <integer> ] [
210N/A min-ns-dots <integer> ] [ qname-wait-recurse <boolean> ];
210N/A rfc2308-type1 <boolean>; // not yet implemented
210N/A root-delegation-only [ exclude { <quoted_string>; ... } ];
210N/A rrset-order { [ class <string> ] [ type <string> ] [ name
210N/A <quoted_string> ] <string> <string>; ... };
210N/A secroots-file <quoted_string>;
210N/A serial-queries <integer>; // obsolete
210N/A serial-query-rate <integer>;
210N/A serial-update-method ( increment | unixtime | date );
210N/A server-id ( <quoted_string> | none | hostname );
210N/A servfail-ttl <ttlval>;
210N/A session-keyalg <string>;
210N/A session-keyfile ( <quoted_string> | none );
210N/A session-keyname <string>;
210N/A sig-signing-nodes <integer>;
210N/A sig-signing-signatures <integer>;
210N/A sig-signing-type <integer>;
210N/A sig-validity-interval <integer> [ <integer> ];
210N/A sit-secret <string>; // not configured
210N/A sortlist { <address_match_element>; ... };
210N/A stacksize <size>;
210N/A startup-notify-rate <integer>;
210N/A statistics-file <quoted_string>;
210N/A statistics-interval <integer>; // not yet implemented
210N/A suppress-initial-notify <boolean>; // not yet implemented
210N/A tcp-clients <integer>;
210N/A tcp-listen-queue <integer>;
210N/A tkey-dhkey <quoted_string> <integer>;
210N/A tkey-domain <quoted_string>;
210N/A tkey-gssapi-credential <quoted_string>;
210N/A tkey-gssapi-keytab <quoted_string>;
210N/A topology { <address_match_element>; ... }; // not implemented
210N/A transfer-format ( many-answers | one-answer );
210N/A transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * )
210N/A ] [ dscp <integer> ];
210N/A transfers-in <integer>;
210N/A transfers-out <integer>;
210N/A transfers-per-ns <integer>;
210N/A treat-cr-as-space <boolean>; // obsolete
210N/A try-tcp-refresh <boolean>;
210N/A update-check-ksk <boolean>;
210N/A use-alt-transfer-source <boolean>;
210N/A use-id-pool <boolean>; // obsolete
210N/A use-ixfr <boolean>;
210N/A use-queryport-pool <boolean>; // obsolete
210N/A use-v4-udp-ports { <portrange>; ... };
210N/A use-v6-udp-ports { <portrange>; ... };
210N/A version ( <quoted_string> | none );
210N/A zero-no-soa-ttl <boolean>;
210N/A zero-no-soa-ttl-cache <boolean>;
210N/A zone-statistics <zonestat>;
210N/A};
210N/A
210N/Aserver <netprefix> {
210N/A bogus <boolean>;
210N/A edns <boolean>;
210N/A edns-udp-size <integer>;
210N/A edns-version <integer>;
210N/A keys <server_key>;
210N/A max-udp-size <integer>;
210N/A notify-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A notify-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * ) ]
210N/A [ dscp <integer> ];
210N/A provide-ixfr <boolean>;
210N/A query-source <querysource4>;
210N/A query-source-v6 <querysource6>;
210N/A request-expire <boolean>;
210N/A request-ixfr <boolean>;
210N/A request-nsid <boolean>;
210N/A request-sit <boolean>; // not configured
210N/A support-ixfr <boolean>; // obsolete
210N/A transfer-format ( many-answers | one-answer );
210N/A transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * )
210N/A ] [ dscp <integer> ];
210N/A transfers <integer>;
210N/A};
210N/A
210N/Astatistics-channels {
210N/A inet ( <ipv4_address> | <ipv6_address> | * ) [ port ( <integer> | *
210N/A ) ] [ allow { <address_match_element>; ... } ];
210N/A};
210N/A
210N/Atrusted-keys { <string> <integer> <integer> <integer> <quoted_string>; ... };
210N/A
210N/Aview <string> <optional_class> {
210N/A acache-cleaning-interval <integer>;
210N/A acache-enable <boolean>;
210N/A additional-from-auth <boolean>;
210N/A additional-from-cache <boolean>;
210N/A allow-new-zones <boolean>;
210N/A allow-notify { <address_match_element>; ... };
210N/A allow-query { <address_match_element>; ... };
210N/A allow-query-cache { <address_match_element>; ... };
210N/A allow-query-cache-on { <address_match_element>; ... };
210N/A allow-query-on { <address_match_element>; ... };
210N/A allow-recursion { <address_match_element>; ... };
210N/A allow-recursion-on { <address_match_element>; ... };
210N/A allow-transfer { <address_match_element>; ... };
210N/A allow-update { <address_match_element>; ... };
210N/A allow-update-forwarding { <address_match_element>; ... };
210N/A allow-v6-synthesis { <address_match_element>; ... }; // obsolete
210N/A also-notify [ port <integer> ] [ dscp <integer> ] { ( <masters> |
210N/A <ipv4_address> [ port <integer> ] | <ipv6_address> [ port
210N/A <integer> ] ) [ key <string> ]; ... };
210N/A alt-transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * )
210N/A ] [ dscp <integer> ];
210N/A alt-transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> |
210N/A * ) ] [ dscp <integer> ];
210N/A attach-cache <string>;
210N/A auth-nxdomain <boolean>; // default changed
210N/A auto-dnssec ( allow | maintain | off );
210N/A cache-file <quoted_string>;
210N/A check-dup-records ( fail | warn | ignore );
210N/A check-integrity <boolean>;
210N/A check-mx ( fail | warn | ignore );
210N/A check-mx-cname ( fail | warn | ignore );
210N/A check-names ( master | slave | response ) ( fail | warn | ignore );
210N/A check-sibling <boolean>;
210N/A check-spf ( warn | ignore );
210N/A check-srv-cname ( fail | warn | ignore );
210N/A check-wildcard <boolean>;
210N/A cleaning-interval <integer>;
210N/A clients-per-query <integer>;
210N/A deny-answer-addresses { <address_match_element>; ... } [
210N/A except-from { <quoted_string>; ... } ];
210N/A deny-answer-aliases { <quoted_string>; ... } [ except-from {
210N/A <quoted_string>; ... } ];
210N/A dialup <dialuptype>;
210N/A disable-algorithms <string> { <string>; ... };
210N/A disable-ds-digests <string> { <string>; ... };
210N/A disable-empty-zone <string>;
210N/A dlz <string> {
210N/A database <string>;
210N/A search <boolean>;
210N/A };
210N/A dns64 <netprefix> {
210N/A break-dnssec <boolean>;
210N/A clients { <address_match_element>; ... };
210N/A exclude { <address_match_element>; ... };
210N/A mapped { <address_match_element>; ... };
210N/A recursive-only <boolean>;
210N/A suffix <ipv6_address>;
210N/A };
210N/A dns64-contact <string>;
210N/A dns64-server <string>;
210N/A dnssec-accept-expired <boolean>;
210N/A dnssec-dnskey-kskonly <boolean>;
210N/A dnssec-enable <boolean>;
210N/A dnssec-loadkeys-interval <integer>;
210N/A dnssec-lookaside ( <string> trust-anchor <string> | auto | no );
210N/A dnssec-must-be-secure <string> <boolean>;
210N/A dnssec-secure-to-insecure <boolean>;
210N/A dnssec-update-mode ( maintain | no-resign );
210N/A dnssec-validation ( yes | no | auto );
210N/A dual-stack-servers [ port <integer> ] { ( <quoted_string> [ port
210N/A <integer> ] [ dscp <integer> ] | <ipv4_address> [ port
210N/A <integer> ] [ dscp <integer> ] | <ipv6_address> [ port
210N/A <integer> ] [ dscp <integer> ] ); ... };
210N/A edns-udp-size <integer>;
210N/A empty-contact <string>;
210N/A empty-server <string>;
210N/A empty-zones-enable <boolean>;
210N/A fetch-glue <boolean>; // obsolete
210N/A filter-aaaa { <address_match_element>; ... }; // not configured
210N/A filter-aaaa-on-v4 <filter_aaaa>; // not configured
210N/A filter-aaaa-on-v6 <filter_aaaa>; // not configured
210N/A forward ( first | only );
210N/A forwarders [ port <integer> ] [ dscp <integer> ] { ( <ipv4_address>
210N/A | <ipv6_address> ) [ port <integer> ] [ dscp <integer> ]; ... };
210N/A inline-signing <boolean>;
210N/A ixfr-from-differences <ixfrdiff>;
210N/A key <string> {
210N/A algorithm <string>;
210N/A secret <string>;
210N/A };
210N/A key-directory <quoted_string>;
210N/A lame-ttl <ttlval>;
210N/A maintain-ixfr-base <boolean>; // obsolete
210N/A managed-keys { <string> <string> <integer> <integer> <integer>
210N/A <quoted_string>; ... };
210N/A masterfile-format ( text | raw | map );
210N/A masterfile-style ( full | relative );
210N/A match-clients { <address_match_element>; ... };
210N/A match-destinations { <address_match_element>; ... };
210N/A match-recursive-only <boolean>;
210N/A max-acache-size <size_no_default>;
210N/A max-cache-size <size_no_default>;
210N/A max-cache-ttl <integer>;
210N/A max-clients-per-query <integer>;
210N/A max-ixfr-log-size <size>; // obsolete
210N/A max-journal-size <size_no_default>;
210N/A max-ncache-ttl <integer>;
210N/A max-recursion-depth <integer>;
210N/A max-recursion-queries <integer>;
210N/A max-refresh-time <integer>;
210N/A max-retry-time <integer>;
210N/A max-transfer-idle-in <integer>;
210N/A max-transfer-idle-out <integer>;
210N/A max-transfer-time-in <integer>;
210N/A max-transfer-time-out <integer>;
210N/A max-udp-size <integer>;
210N/A max-zone-ttl <maxttl_no_default>;
210N/A min-refresh-time <integer>;
210N/A min-retry-time <integer>;
210N/A min-roots <integer>; // not implemented
210N/A minimal-responses <boolean>;
210N/A multi-master <boolean>;
210N/A no-case-compress { <address_match_element>; ... };
210N/A nosit-udp-size <integer>; // not configured
210N/A notify <notifytype>;
210N/A notify-delay <integer>;
210N/A notify-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A notify-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * ) ]
210N/A [ dscp <integer> ];
210N/A notify-to-soa <boolean>;
210N/A nsec3-test-zone <boolean>; // test only
210N/A nta-lifetime <ttlval>;
210N/A nta-recheck <ttlval>;
210N/A preferred-glue <string>;
210N/A prefetch <integer> [ <integer> ];
210N/A provide-ixfr <boolean>;
210N/A query-source <querysource4>;
210N/A query-source-v6 <querysource6>;
210N/A queryport-pool-ports <integer>; // obsolete
210N/A queryport-pool-updateinterval <integer>; // obsolete
210N/A rate-limit {
210N/A all-per-second <integer>;
210N/A errors-per-second <integer>;
210N/A exempt-clients { <address_match_element>; ... };
210N/A ipv4-prefix-length <integer>;
210N/A ipv6-prefix-length <integer>;
210N/A log-only <boolean>;
210N/A max-table-size <integer>;
210N/A min-table-size <integer>;
210N/A nodata-per-second <integer>;
210N/A nxdomains-per-second <integer>;
210N/A qps-scale <integer>;
210N/A referrals-per-second <integer>;
210N/A responses-per-second <integer>;
210N/A slip <integer>;
210N/A window <integer>;
210N/A };
210N/A recursion <boolean>;
210N/A request-expire <boolean>;
210N/A request-ixfr <boolean>;
210N/A request-nsid <boolean>;
210N/A request-sit <boolean>; // not configured
210N/A resolver-query-timeout <integer>;
210N/A response-policy { zone <quoted_string> [ policy ( given | disabled
210N/A | passthru | no-op | drop | tcp-only | nxdomain | nodata |
210N/A cname <quoted_string> ) ] [ recursive-only <boolean> ] [
210N/A max-policy-ttl <integer> ]; ... } [ recursive-only <boolean> ]
210N/A [ break-dnssec <boolean> ] [ max-policy-ttl <integer> ] [
210N/A min-ns-dots <integer> ] [ qname-wait-recurse <boolean> ];
210N/A rfc2308-type1 <boolean>; // not yet implemented
210N/A root-delegation-only [ exclude { <quoted_string>; ... } ];
210N/A rrset-order { [ class <string> ] [ type <string> ] [ name
210N/A <quoted_string> ] <string> <string>; ... };
210N/A serial-update-method ( increment | unixtime | date );
210N/A server <netprefix> {
210N/A bogus <boolean>;
210N/A edns <boolean>;
210N/A edns-udp-size <integer>;
210N/A edns-version <integer>;
210N/A keys <server_key>;
210N/A max-udp-size <integer>;
210N/A notify-source ( <ipv4_address> | * ) [ port ( <integer> | *
210N/A ) ] [ dscp <integer> ];
210N/A notify-source-v6 ( <ipv6_address> | * ) [ port ( <integer>
210N/A | * ) ] [ dscp <integer> ];
210N/A provide-ixfr <boolean>;
210N/A query-source <querysource4>;
210N/A query-source-v6 <querysource6>;
210N/A request-expire <boolean>;
210N/A request-ixfr <boolean>;
210N/A request-nsid <boolean>;
210N/A request-sit <boolean>; // not configured
210N/A support-ixfr <boolean>; // obsolete
210N/A transfer-format ( many-answers | one-answer );
210N/A transfer-source ( <ipv4_address> | * ) [ port ( <integer> |
210N/A * ) ] [ dscp <integer> ];
210N/A transfer-source-v6 ( <ipv6_address> | * ) [ port (
210N/A <integer> | * ) ] [ dscp <integer> ];
210N/A transfers <integer>;
210N/A };
210N/A servfail-ttl <ttlval>;
210N/A sig-signing-nodes <integer>;
210N/A sig-signing-signatures <integer>;
210N/A sig-signing-type <integer>;
210N/A sig-validity-interval <integer> [ <integer> ];
210N/A sortlist { <address_match_element>; ... };
210N/A suppress-initial-notify <boolean>; // not yet implemented
210N/A topology { <address_match_element>; ... }; // not implemented
210N/A transfer-format ( many-answers | one-answer );
210N/A transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * )
210N/A ] [ dscp <integer> ];
210N/A trusted-keys { <string> <integer> <integer> <integer>
210N/A <quoted_string>; ... };
210N/A try-tcp-refresh <boolean>;
210N/A update-check-ksk <boolean>;
210N/A use-alt-transfer-source <boolean>;
210N/A use-queryport-pool <boolean>; // obsolete
210N/A zero-no-soa-ttl <boolean>;
210N/A zero-no-soa-ttl-cache <boolean>;
210N/A zone <string> <optional_class> {
210N/A allow-notify { <address_match_element>; ... };
210N/A allow-query { <address_match_element>; ... };
210N/A allow-query-on { <address_match_element>; ... };
210N/A allow-transfer { <address_match_element>; ... };
210N/A allow-update { <address_match_element>; ... };
210N/A allow-update-forwarding { <address_match_element>; ... };
210N/A also-notify [ port <integer> ] [ dscp <integer> ] { (
210N/A <masters> | <ipv4_address> [ port <integer> ] |
210N/A <ipv6_address> [ port <integer> ] ) [ key <string> ];
210N/A ... };
210N/A alt-transfer-source ( <ipv4_address> | * ) [ port (
210N/A <integer> | * ) ] [ dscp <integer> ];
210N/A alt-transfer-source-v6 ( <ipv6_address> | * ) [ port (
210N/A <integer> | * ) ] [ dscp <integer> ];
210N/A auto-dnssec ( allow | maintain | off );
210N/A check-dup-records ( fail | warn | ignore );
210N/A check-integrity <boolean>;
210N/A check-mx ( fail | warn | ignore );
210N/A check-mx-cname ( fail | warn | ignore );
210N/A check-names ( fail | warn | ignore );
210N/A check-sibling <boolean>;
210N/A check-spf ( warn | ignore );
210N/A check-srv-cname ( fail | warn | ignore );
210N/A check-wildcard <boolean>;
210N/A database <string>;
210N/A delegation-only <boolean>;
210N/A dialup <dialuptype>;
210N/A dlz <string>;
210N/A dnssec-dnskey-kskonly <boolean>;
210N/A dnssec-loadkeys-interval <integer>;
210N/A dnssec-secure-to-insecure <boolean>;
210N/A dnssec-update-mode ( maintain | no-resign );
210N/A file <quoted_string>;
210N/A forward ( first | only );
210N/A forwarders [ port <integer> ] [ dscp <integer> ] { (
210N/A <ipv4_address> | <ipv6_address> ) [ port <integer> ] [
210N/A dscp <integer> ]; ... };
210N/A in-view <string>;
210N/A inline-signing <boolean>;
210N/A ixfr-base <quoted_string>; // obsolete
210N/A ixfr-from-differences <boolean>;
210N/A ixfr-tmp-file <quoted_string>; // obsolete
210N/A journal <quoted_string>;
210N/A key-directory <quoted_string>;
210N/A maintain-ixfr-base <boolean>; // obsolete
210N/A masterfile-format ( text | raw | map );
210N/A masterfile-style ( full | relative );
210N/A masters [ port <integer> ] [ dscp <integer> ] { ( <masters>
210N/A | <ipv4_address> [ port <integer> ] | <ipv6_address> [
210N/A port <integer> ] ) [ key <string> ]; ... };
210N/A max-ixfr-log-size <size>; // obsolete
210N/A max-journal-size <size_no_default>;
210N/A max-refresh-time <integer>;
210N/A max-retry-time <integer>;
210N/A max-transfer-idle-in <integer>;
210N/A max-transfer-idle-out <integer>;
210N/A max-transfer-time-in <integer>;
210N/A max-transfer-time-out <integer>;
210N/A max-zone-ttl <maxttl_no_default>;
210N/A min-refresh-time <integer>;
210N/A min-retry-time <integer>;
210N/A multi-master <boolean>;
210N/A notify <notifytype>;
210N/A notify-delay <integer>;
210N/A notify-source ( <ipv4_address> | * ) [ port ( <integer> | *
210N/A ) ] [ dscp <integer> ];
210N/A notify-source-v6 ( <ipv6_address> | * ) [ port ( <integer>
210N/A | * ) ] [ dscp <integer> ];
210N/A notify-to-soa <boolean>;
210N/A nsec3-test-zone <boolean>; // test only
210N/A pubkey <integer> <integer> <integer>
210N/A <quoted_string>; // obsolete
210N/A request-expire <boolean>;
210N/A request-ixfr <boolean>;
210N/A serial-update-method ( increment | unixtime | date );
210N/A server-addresses { ( <ipv4_address> | <ipv6_address> ) [
210N/A port <integer> ]; ... };
210N/A server-names { <quoted_string>; ... };
210N/A sig-signing-nodes <integer>;
210N/A sig-signing-signatures <integer>;
210N/A sig-signing-type <integer>;
210N/A sig-validity-interval <integer> [ <integer> ];
210N/A transfer-source ( <ipv4_address> | * ) [ port ( <integer> |
210N/A * ) ] [ dscp <integer> ];
210N/A transfer-source-v6 ( <ipv6_address> | * ) [ port (
210N/A <integer> | * ) ] [ dscp <integer> ];
210N/A try-tcp-refresh <boolean>;
210N/A type ( master | slave | stub | static-stub | hint | forward
210N/A | delegation-only | redirect );
210N/A update-check-ksk <boolean>;
210N/A update-policy ( local | { ( grant | deny ) <string> ( name
210N/A | subdomain | wildcard | self | selfsub | selfwild |
210N/A krb5-self | ms-self | krb5-subdomain | ms-subdomain |
210N/A tcp-self | 6to4-self | zonesub | external ) [ <string>
210N/A ] <rrtypelist>; ... };
210N/A use-alt-transfer-source <boolean>;
210N/A zero-no-soa-ttl <boolean>;
210N/A zone-statistics <zonestat>;
210N/A };
210N/A zone-statistics <zonestat>;
210N/A};
210N/A
210N/Azone <string> <optional_class> {
210N/A allow-notify { <address_match_element>; ... };
210N/A allow-query { <address_match_element>; ... };
210N/A allow-query-on { <address_match_element>; ... };
210N/A allow-transfer { <address_match_element>; ... };
210N/A allow-update { <address_match_element>; ... };
210N/A allow-update-forwarding { <address_match_element>; ... };
210N/A also-notify [ port <integer> ] [ dscp <integer> ] { ( <masters> |
210N/A <ipv4_address> [ port <integer> ] | <ipv6_address> [ port
210N/A <integer> ] ) [ key <string> ]; ... };
210N/A alt-transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * )
210N/A ] [ dscp <integer> ];
210N/A alt-transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> |
210N/A * ) ] [ dscp <integer> ];
210N/A auto-dnssec ( allow | maintain | off );
210N/A check-dup-records ( fail | warn | ignore );
210N/A check-integrity <boolean>;
210N/A check-mx ( fail | warn | ignore );
210N/A check-mx-cname ( fail | warn | ignore );
210N/A check-names ( fail | warn | ignore );
210N/A check-sibling <boolean>;
210N/A check-spf ( warn | ignore );
210N/A check-srv-cname ( fail | warn | ignore );
210N/A check-wildcard <boolean>;
210N/A database <string>;
210N/A delegation-only <boolean>;
210N/A dialup <dialuptype>;
210N/A dlz <string>;
210N/A dnssec-dnskey-kskonly <boolean>;
210N/A dnssec-loadkeys-interval <integer>;
210N/A dnssec-secure-to-insecure <boolean>;
210N/A dnssec-update-mode ( maintain | no-resign );
210N/A file <quoted_string>;
210N/A forward ( first | only );
210N/A forwarders [ port <integer> ] [ dscp <integer> ] { ( <ipv4_address>
210N/A | <ipv6_address> ) [ port <integer> ] [ dscp <integer> ]; ... };
210N/A in-view <string>;
210N/A inline-signing <boolean>;
210N/A ixfr-base <quoted_string>; // obsolete
210N/A ixfr-from-differences <boolean>;
210N/A ixfr-tmp-file <quoted_string>; // obsolete
210N/A journal <quoted_string>;
210N/A key-directory <quoted_string>;
210N/A maintain-ixfr-base <boolean>; // obsolete
210N/A masterfile-format ( text | raw | map );
210N/A masterfile-style ( full | relative );
210N/A masters [ port <integer> ] [ dscp <integer> ] { ( <masters> |
210N/A <ipv4_address> [ port <integer> ] | <ipv6_address> [ port
210N/A <integer> ] ) [ key <string> ]; ... };
210N/A max-ixfr-log-size <size>; // obsolete
210N/A max-journal-size <size_no_default>;
210N/A max-refresh-time <integer>;
210N/A max-retry-time <integer>;
210N/A max-transfer-idle-in <integer>;
210N/A max-transfer-idle-out <integer>;
210N/A max-transfer-time-in <integer>;
210N/A max-transfer-time-out <integer>;
210N/A max-zone-ttl <maxttl_no_default>;
210N/A min-refresh-time <integer>;
210N/A min-retry-time <integer>;
210N/A multi-master <boolean>;
210N/A notify <notifytype>;
210N/A notify-delay <integer>;
210N/A notify-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A notify-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * ) ]
210N/A [ dscp <integer> ];
210N/A notify-to-soa <boolean>;
210N/A nsec3-test-zone <boolean>; // test only
210N/A pubkey <integer> <integer> <integer> <quoted_string>; // obsolete
210N/A request-expire <boolean>;
210N/A request-ixfr <boolean>;
210N/A serial-update-method ( increment | unixtime | date );
210N/A server-addresses { ( <ipv4_address> | <ipv6_address> ) [ port
210N/A <integer> ]; ... };
210N/A server-names { <quoted_string>; ... };
210N/A sig-signing-nodes <integer>;
210N/A sig-signing-signatures <integer>;
210N/A sig-signing-type <integer>;
210N/A sig-validity-interval <integer> [ <integer> ];
210N/A transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ] [
210N/A dscp <integer> ];
210N/A transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * )
210N/A ] [ dscp <integer> ];
210N/A try-tcp-refresh <boolean>;
210N/A type ( master | slave | stub | static-stub | hint | forward |
210N/A delegation-only | redirect );
210N/A update-check-ksk <boolean>;
210N/A update-policy ( local | { ( grant | deny ) <string> ( name |
210N/A subdomain | wildcard | self | selfsub | selfwild | krb5-self |
210N/A ms-self | krb5-subdomain | ms-subdomain | tcp-self | 6to4-self
210N/A | zonesub | external ) [ <string> ] <rrtypelist>; ... };
210N/A use-alt-transfer-source <boolean>;
210N/A zero-no-soa-ttl <boolean>;
210N/A zone-statistics <zonestat>;
210N/A};
210N/A
210N/A