On Thu, 8 Oct 2009, Vadim wrote: > But As far as I know NSD doesn't have a cache, so under heavy load > NSD will load disk. My zone with 1.2 Million records ad takes 120MB of RAM. Nsd does not need a cache. > I have plenty of zones, so I want to protect my > authoritative > servers from burst of requests, ddos and so on. Protect from what? It seems like you want to protect the auth servers on the inside, while they need to be contacted by the inside and the outside? In that case, like others have said before, use a secondary on outside pulling from your primary on the inside. Paul