help on strange dig info

2009-04-12 Thread Tech W.

Hello,


I digged a domain name as below:

r...@dev1:~# dig www.csfunds.com.cn

; <<>> DiG 9.5.0-P2 <<>> www.csfunds.com.cn
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23283
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 2, ADDITIONAL: 0

;; QUESTION SECTION:
;www.csfunds.com.cn.IN  A

;; ANSWER SECTION:
www.csfunds.com.cn. 86149   IN  CNAME   www.f5.csfunds.com.cn.
www.f5.csfunds.com.cn.  30  IN  A   124.207.40.24

;; AUTHORITY SECTION:
f5.csfunds.com.cn.  85769   IN  NS  lc2.f5.csfunds.com.cn.
f5.csfunds.com.cn.  85769   IN  NS  lc1.f5.csfunds.com.cn.


It said f5.csfunds.com.cn's nameservers are lc1.f5.csfunds.com.cn and 
lc2.f5.csfunds.com.cn.


But, I can't dig the info for both lc1 and lc2.

r...@dev1:~# dig lc1.f5.csfunds.com.cn

; <<>> DiG 9.5.0-P2 <<>> lc1.f5.csfunds.com.cn
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 29538
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;lc1.f5.csfunds.com.cn. IN  A


r...@dev1:~# dig lc2.f5.csfunds.com.cn

; <<>> DiG 9.5.0-P2 <<>> lc2.f5.csfunds.com.cn
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 39091
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;lc2.f5.csfunds.com.cn. IN  A



This let me really confused.
When clients can't get IP addr for lc1 and lc2, how clients query the domain 
records in zone of f5.csfunds.com.cn?

Thanks for your helps.

Regards.
Ken.


  Yahoo!7 recommends that you update your browser to the new Internet 
Explorer 8.Get it now.
___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


Re: help on strange dig info

2009-04-12 Thread Gregory Hicks

> Date: Sun, 12 Apr 2009 15:22:42 +0800 (CST)
> From: "Tech W." 
> Subject: help on strange dig info
> To: bind-users@lists.isc.org
> 
> 
> Hello,
> 
> 
> I digged a domain name as below:
> 
> r...@dev1:~# dig www.csfunds.com.cn
> 
> ; <<>> DiG 9.5.0-P2 <<>> www.csfunds.com.cn
> ;; global options:  printcmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23283
> ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 2, ADDITIONAL: 0
> 
> ;; QUESTION SECTION:
> ;www.csfunds.com.cn.IN  A
> 
> ;; ANSWER SECTION:
> www.csfunds.com.cn. 86149   IN  CNAME   www.f5.csfunds.com.cn.
> www.f5.csfunds.com.cn.  30  IN  A   124.207.40.24
> 
> ;; AUTHORITY SECTION:
> f5.csfunds.com.cn.  85769   IN  NS  lc2.f5.csfunds.com.cn.
> f5.csfunds.com.cn.  85769   IN  NS  lc1.f5.csfunds.com.cn.
> 
> 
> It said f5.csfunds.com.cn's nameservers are lc1.f5.csfunds.com.cn and 
lc2.f5.csfunds.com.cn.
> 
> 
> But, I can't dig the info for both lc1 and lc2.

Those are lame servers, kind sir.  In other words, the domain is
delegated to those servers but those servers don't recognize their
authority.

Regards,
Gregory Hicks
> 
> r...@dev1:~# dig lc1.f5.csfunds.com.cn
> 
> ; <<>> DiG 9.5.0-P2 <<>> lc1.f5.csfunds.com.cn
> ;; global options:  printcmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 29538
> ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
> 
> ;; QUESTION SECTION:
> ;lc1.f5.csfunds.com.cn. IN  A
> 
> 
> r...@dev1:~# dig lc2.f5.csfunds.com.cn
> 
> ; <<>> DiG 9.5.0-P2 <<>> lc2.f5.csfunds.com.cn
> ;; global options:  printcmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 39091
> ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
> 
> ;; QUESTION SECTION:
> ;lc2.f5.csfunds.com.cn. IN  A
> 
> 
> 
> This let me really confused.
> When clients can't get IP addr for lc1 and lc2, how clients query the 
domain records in zone of f5.csfunds.com.cn?
> 
> Thanks for your helps.
> 
> Regards.
> Ken.
> 
> 
>   Yahoo!7 recommends that you update your browser to the new 
Internet Explorer 8.Get it now.
> ___
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users

-
Gregory Hicks   | Principal Systems Engineer
| Direct:   408.569.7928

People sleep peaceably in their beds at night only because rough men
stand ready to do violence on their behalf -- George Orwell

The price of freedom is eternal vigilance.  -- Thomas Jefferson

"The best we can hope for concerning the people at large is that they
be properly armed." --Alexander Hamilton

___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


Re: help on strange dig info

2009-04-12 Thread Tech W.



--- On Sun, 12/4/09, Gregory Hicks  wrote:

> From: Gregory Hicks 
> Subject: Re: help on strange dig info
> To: bind-users@lists.isc.org, tech...@yahoo.com.cn
> Received: Sunday, 12 April, 2009, 3:33 PM
> 
> > I digged a domain name as below:
> > 
> > r...@dev1:~# dig www.csfunds.com.cn
> > 
> > ; <<>> DiG 9.5.0-P2 <<>>
> www.csfunds.com.cn
> > ;; global options:  printcmd
> > ;; Got answer:
> > ;; ->>HEADER<<- opcode: QUERY, status:
> NOERROR, id: 23283
> > ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 2,
> ADDITIONAL: 0
> > 
> > ;; QUESTION SECTION:
> > ;www.csfunds.com.cn.         
>   IN      A
> > 
> > ;; ANSWER SECTION:
> > www.csfunds.com.cn. 
>    86149   IN   
>   CNAME   www.f5.csfunds.com.cn.
> > www.f5.csfunds.com.cn.  30     
> IN      A   
>    124.207.40.24
> > 
> > ;; AUTHORITY SECTION:
> > f5.csfunds.com.cn.     
> 85769   IN      NS 
>     lc2.f5.csfunds.com.cn.
> > f5.csfunds.com.cn.     
> 85769   IN      NS 
>     lc1.f5.csfunds.com.cn.
> > 
> > 
> > It said f5.csfunds.com.cn's nameservers are
> lc1.f5.csfunds.com.cn and 
> lc2.f5.csfunds.com.cn.
> > 
> > 
> > But, I can't dig the info for both lc1 and lc2.
> 
> Those are lame servers, kind sir.  In other words, the
> domain is
> delegated to those servers but those servers don't
> recognize their
> authority.
> 


Thanks Hicks.
Why F5's big-ip has been using a lame server there?

Regards.




  The new Internet Explorer 8 optimised for Yahoo!7: Faster, Safer, Easier.
___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


Re: about ns record in child domain

2009-04-12 Thread Chris Buxton

On Apr 11, 2009, at 9:08 PM, Tech W. wrote:

--- On Sun, 12/4/09, Chris Buxton  wrote:

You've confused NS records with A records. Create the NS
record; omit the A record.

cdn.example.com.  IN  NS otherdns.example.com.




Thanks Chris.
Do you mean in a zone, we have a NS record, but we don't need to  
have an A record corresponding to that NS record?


That's correct. The A record only needs to exist in the zone that  
logically contains its name.


Chris Buxton
Professional Services
Men & Mice

___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users