The available configuration options are too much for a simple service like dns forwarding.
As VyOS 1.2 already deprecated the command set service dns forwarding listen-on we should remove it rather sooner then later. In addition to this removal we should consider also to remove some more weeds.
Proposal is to remove the following commands as we now have a full blown DNS recursor:
- set service dns forwarding listen-on <interface>
- set service dns forwarding dhcp <interface>
We could also consider extending the CLI to specify only allowed networks which can use the DNS recursor. As of now, we allow 0.0.0.0/0 and ::/0