Is it possible to specify both an ACL and TSIG key for zone transfer security? I want only a select number of IP addresses to be able to transfer zones and also require a TSIG key for those same devices. I'm not sure how the ACLs are built if it is an "any" or "all" condition. Thanks!

Zone transfer ACL's allow you to allow/deny zone transfers using either an IP address or TSIG key. You can certainly configure rules for IP or TSIG key, but one or the other would be fine.




