Configure Cisco Jabber DNS and Single Domain using Response Policy Zone (RPZ) and a single BIND9 DNS server

Cisco recommends dual DNS: public (external) and local (internal) DNS in order that Mobile and Remote Access can work more efficiently.

Pinpoint entries (a zone created for a single host only) as suggested by Cisco could be a solution, but our DNS server is authoritative for the parent domain, so this wouldn't work.

With the follwing setup and by using RPZ, jabber requests coming from the internet, are forwarded to Expressway-Edge and requests coming from the internal network are forwarded to Expressway-Core.

Public (External) Records needed:      SRV 10 10 8443

Local (Internal) Records needed:        SRV    10 10 8443         SRV    10 10 8443

Cisco states that a client first searches for internal DNS records:
For example, Adam McKenzie's services domain is when he starts the client. The client then issues the following query:

We will be using RPZ, so that the client gets different DNS results depending on which DNS is using for recursion (Public or Private).
Our DNS server is authoritative for all our domains and recursive allowing queries only from internal network (allow-recursion { ournets; };).

First, create the RPZ zone file to your bind9 recursor. This is where all the overrides will be placed.
I copied the file from and modified it according to our needs.


$TTL 3600

@               IN SOA  localhost. (
                       201702135 ; Serial number
                       60        ; Refresh every minute
                       60        ; Retry every minute
                       432000    ; Expire in 5 days
                       60 )      ; negative caching ttl 1 minute
                IN NS   LOCALHOST.
; IN CNAME *. ; return NODATA for internal queries - Probably not needed          SRV     10 10 8443 ;internal only           SRV     10 10 8443 ;internal only

In my Debian Buster BIND configuration, I use seperate config files in named.conf:

include "/etc/bind/named.conf.options";
include "/etc/bind/named.conf.local";
include "/etc/bind/named.conf.log";

If you use a single config file, then put the following parts in the same file, usually named.conf.
Enable logging of RPZ requests, it is a goood thing to know what's going on:


        channel rpzlog {
                file "/var/log/rpz.log" versions 14 size 1m;
                print-time yes;
                print-category yes;
                print-severity yes;
                severity info;
        category rpz { rpzlog; };

In your domain main zone file, among your other records, you have to add the following record.
This should be available publicly so that remote clients can access your Cisco Expressway Edge.
In my case, this zone is also transferred to our domain slaves. zone:

_collab-edge._tls       SRV     10 10 8443 ; VCS Expressway or Cisco Expressway-E server

Then, add the zone in your config file:


zone "rpz.local" {
        type master;
        file "db.rpz.local";
        allow-update { none; };
        allow-transfer { none; };

Finally, enable the Response Policy Zone:


        response-policy {
                zone "rpz.local";

Restart Bind and reload the zone

sudo /etc/init.d/bind9 restart
sudo rndc reload rpz.local

Do some tests from some clients and check the rpz.log file!
When querying locally for, you should get a result and see some Local-Data rewrite for your queries.
When querying remotely for, you should get no answer.


Δημοφιλείς αναρτήσεις από αυτό το ιστολόγιο

Get Telegram notifications for APC UPS using SNMP traps in Linux

Using IFTTT recipe to run a shell script

Setting up your openwrt adsl router for Forthnet IPv6 (Dual Stack) - Static Pilot