Warda-DNSDocs

Network → DNS services → Answers (PUT /api/v1/dns-services/policy {"blocked_response": "null"|"nxdomain"|"refused", "rate_limit": n}, administrators; meta blocked_response and rate_limit, applied at once and at the start):

  • the answer to a blocked name: the null address (0.0.0.0 for A, :: for AAAA, an empty answer for the other types; the default), NXDOMAIN, or REFUSED (most devices then ask their other DNS server, if they have one). The names of the category bypass always get NXDOMAIN;
  • the queries a second allowed to each device (0: no limit, the default; 10 to 10,000): a bucket per client address (each IPv6 address apart: the devices of a home share one /64), bursts of twice the rate; beyond, the query is answered REFUSED, is not written to the journal and is counted (rate_limited in the metrics). The box itself is never limited. Leave 0 when the router sends Warda the queries of the whole network (it is then one client).