Securing DNS (BIND/named)

For default options only allow-queries only for internal network; then allow-query for all for zones you're authoritative for. A slave doesn't need to allow zone transfers.