> hi,
> one more question:
> is there a possibility to alway allow updates from localhost regardless of

of =
> a view or do a i have to write a own view with match-clients { localhost; }

localhost; }=
> ; with all my zones in it?

The problem you have is not exactly an "allow" or "deny" problem.
Remember, when you request a zone transfer from named it needs to know
which zone you want. Because you are using views two zones with the same
name can exist in different views. Therefore, named must have a way of
determining which zone *and* which view you are requesting before it can
honor your request. There are 2 ways named determines the view for a
given request. One is by the source IP of the request (match-clients) and
the other is the destination IP of the request (match-destinations). Check
the ARM for the syntax for these options. It is worth noting that the use
of 'match-destinations' will require multiple IP addresses on the name

So, the short answer to your question is most likely no.



