By default named/bind will listen on all available interfaces. If you only want it to respond to local clients can't you just set it to listen on the local interface? If so, set it in your named.conf file. Then as long as outside DNS traffic is not being routed to your DNS server's local interface/address you shouldn't have to worry about other people using it. If that is not a option then look into using iptables.
Last edited by fur; 11-23-2005 at 08:35 AM.