Network → DNS services → Answers (PUT /api/v1/dns-services/policy
{"blocked_response": "null"|"nxdomain"|"refused", "rate_limit": n},
administrators; meta blocked_response and rate_limit, applied at once
and at the start):
- the answer to a blocked name: the null address (0.0.0.0 for A, :: for
AAAA, an empty answer for the other types; the default), NXDOMAIN, or
REFUSED (most devices then ask their other DNS server, if they have
one). The names of the category
bypassalways get NXDOMAIN; - the queries a second allowed to each device (0: no limit, the default;
10 to 10,000): a bucket per client address (each IPv6 address apart:
the devices of a home share one /64), bursts of twice the rate; beyond, the query is answered REFUSED,
is not written to the journal and is counted (
rate_limitedin the metrics). The box itself is never limited. Leave 0 when the router sends Warda the queries of the whole network (it is then one client).