<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>It depends what interface you use for auth-server in second
parameter. You have not shared if you have internal and external
interfaces, so I would guess enp2s0f0 is internal interface. If
you want authoritative answers served to internal clients, use
just <code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px">auth-server=<a
href="http://server.home.mydomain.com">server.home.mydomain.com</a><br>
</code></p>
<p><code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px"></code>auth-server
with interface specified is intended to be used on router WAN
interface facing to potentially hostile network. Therefore it does
not do recursive service, but just authoritative on it. That is by
design, but may not be what you wanted.</p>
<p>For trusted internal network, specify just allowed interface(s).<br>
</p>
<p><font face="monospace">interface=lo<br>
interface=enp20f0</font><br>
<code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px">auth-server=<a
href="http://server.home.mydomain.com">server.home.mydomain.com<br>
</a></code><code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px">auth-zone=<a
href="http://home.mydomain.com">home.mydomain.com</a>,192.168.1.0/24<br>
</code><code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px">host-record=server.home.mydomain.com,192.168.1.50</code></p>
<p><code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px"></code></p>
<p>Cheers,<br>
Petr<code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px"><br>
</code></p>
<div class="moz-cite-prefix">On 06. 11. 23 14:22, John Klimek wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAOEv1kbkCJcUZbOncPakLFumUu19u9gz5ZfhcyaSdrjKzcuRVQ@mail.gmail.com">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<div dir="ltr">
<div>Here is the dnsmasq.conf I'm using. It seems to return
authoritative responses for <a
href="http://home.mydomain.com" moz-do-not-send="true">home.mydomain.com</a>
but if I query anything else it returns REFUSED:</div>
<div><br>
</div>
<div>
<pre
style="margin-top:0px;margin-bottom:0px;border:0px;font-stretch:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;width:auto;max-height:600px;overflow:auto;color:rgb(12,13,14)"><code
style="margin:0px;padding:0px;border:0px;font-style:inherit;font-variant-caps:inherit;font-stretch:inherit;line-height:inherit;font-size-adjust:inherit;font-kerning:inherit;font-variant-alternates:inherit;font-variant-ligatures:inherit;font-variant-numeric:inherit;font-variant-east-asian:inherit;font-feature-settings:inherit;vertical-align:baseline;box-sizing:inherit;border-radius:0px">log-queries
no-resolv
server=8.8.4.4
server=8.8.8.8
auth-server=<a href="http://server.home.mydomain.com"
moz-do-not-send="true">server.home.mydomain.com</a>,enp2s0f0
auth-zone=<a href="http://home.mydomain.com" moz-do-not-send="true">home.mydomain.com</a>,<a
href="http://192.168.1.0/24
host-record=server.home.mydomain.com,192.168.1.50"
moz-do-not-send="true">192.168.1.0/24
host-record=server.home.mydomain.com,192.168.1.50</a></code></pre>
</div>
<div class="gmail_quote">
<blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
</blockquote>
</div>
</div>
<span style="white-space: pre-wrap">
</span></blockquote>
<pre class="moz-signature" cols="72">--
Petr Menšík
Software Engineer, RHEL
Red Hat, <a class="moz-txt-link-freetext" href="http://www.redhat.com/">http://www.redhat.com/</a>
PGP: DFCF908DB7C87E8E529925BC4931CA5B6C9FC5CB</pre>
</body>
</html>