update-policy (nrcmd)					update-policy (nrcmd)


NAME
    update-policy - Configures DNS update policies.

SYNOPSIS
    update-policy <name> create 
    update-policy <name> delete
    update-policy list  
    update-policy listnames
    update-policy <name> show
    update-policy<name> get <attribute>
    update-policy <name> unset <attribute>
    
    update-policy <name> rules add "<value>" [<index>]
    update-policy <name> rules remove <index>

DESCRIPTION
    The update-policy command lets you configure DNS update-policies.
    The most significant property of an update policy is an ordered
    list of rules. The rules are used to restrict or permit updates to
    DNS names. When adding a new rule, enclose the complete string
    in quotation marks. Use the backslash (\) to allow square 
    brackets ([ ]) in the rule.
    
    Note: If an update ACL  has been configured on the zone, 
    any update-policy configuration is ignored.

EXAMPLES
    nrcmd> update-policy test create 
    nrcmd> update-policy test rules add  "grant any wildcard example* SRV"
    nrcmd> update-policy test rules add  "deny 1.1.1.1 wildcard \[a-z\]* A"

STATUS

SEE ALSO

PROPERTIES
  Attributes:

    name[1] (AT_STRING, Required, default: <none>)
        Specifies the name of the Update Policy.

    rules[2] (AT_NLIST(AT_RULE), Optional, default: <none>)
        Lists rules that make up the update policy. Each rule has the
        following syntax:
        	<action> <acl-list> <keyword> <value> <rr-list>
        action:   Can be grant or deny.
        	      grant - will allow an update if the rest of the rule
                          matches.
                  deny  - will deny an update if the rest of the rule
                          matches.
        acl-list: A list of one or more ip addresses, network addresses,
                  keys and/or named acl references. Note key names must be
                  prefixed with "key " (i.e. "key key.example" ).
        keyword:  Can be name, subdomain or wildcard.
         	      name - used to specify a specific RR.
        	      subdomain - used to specify a subdomain name.
        	      wildcard - used to specify a name with wildcard
                  characters.
        value:    The name, sudomain or wildcard value associated with the
                  specified keyword. Note that all values specified are
                  relative to the zone in which they are applied.
                  Therefore it is not necessary to add the zone name to
                  the end of the value.
                  The supported wildcard characters are:
                  *     Will match zero or more characters. For example,
                        the pattern dhcp-* matches all strings with the
                        dhcp- prefix including the string dhcp-.
                  ?     Will match a single character. For example, the
                        pattern zone?.com matches zone1.com, zone2.com,
                        etc but does not match zone.com
                  [...] Will match any characters listed within the
                        brackets. For example, you can provide a range
                        such as 0-9 or a-z. If the pattern also includes
                        the - character, make it the first character in
                        the list (i.e. dhcp[-a-z]*)
        rr-types: A comma delimited list of RR types for this rule. Each RR
        	  type can also be negated using the exclamation point
                  (i.e. !A,!TXT). You can also specify all types the an
                  asterisk (*).

