Re: How can I increase the TTL for the cached entries in my local dns serveder?

2014-03-27 Thread Barry Margolin
In article , Hongyi Zhao wrote: > In addtition, I also want to have long TTL so that I can obtain a short > inquiry respond time. You can't. If a domain operator wants his changes to propagate quickly (like when moving to a new hosting provider, or if using DNS for failover), he has to be abl

How can I increase the TTL for the cached entries in my local dns serveder?

2014-03-27 Thread Hongyi Zhao
Hi all, Currently, I use bind9 as the local dns cache server and a forwarder only server. I set the dnscrpyt-proxy running on local port 50 as the upstream dns server for my bind9 dns cache server. In addtition, I also want to have long TTL so that I can obtain a short inquiry respond time. Fo

Re: High recursive client counts

2014-03-27 Thread Mark Andrews
In message <53349e66.8050...@ksu.edu>, "Lawrence K. Chen, P.Eng." writes: > > > On 03/26/14 04:02, Sam Wilson wrote: > > In article , > > Jason Brandt wrote: > > > >> For now, I've disabled DNS inspection on our firewall, as it is an ancient > >> Cisco firewall services module, and that seems

Re: High recursive client counts

2014-03-27 Thread Lawrence K. Chen, P.Eng.
On 03/26/14 04:02, Sam Wilson wrote: > In article , > Jason Brandt wrote: > >> For now, I've disabled DNS inspection on our firewall, as it is an ancient >> Cisco firewall services module, and that seems to have stabilized things, >> but it's only been 30 minutes or so. Until I get a few days

Re: High recursive client counts

2014-03-27 Thread Eliezer Croitoru
Are you using logs on the bind machine\s? Eliezer On 03/25/2014 04:31 PM, Jason Brandt wrote: We recently migrated to BIND for our internal resolvers, and since the migration, we are experiencing periods of high recursive client counts, which will at times cause the BIND server to quit respondi

Re: DLZ / ISC DHCP query

2014-03-27 Thread Evan Hunt
On Thu, Mar 27, 2014 at 06:58:35PM +, Marty Lee wrote: > BTW, doing a manual Dynamic DNS update using nsupdate works fine - the A > and TXT records are created without any problem and the A record isn?t > then deleted, so it?s something to do with the DHCP server and it?s > interaction with Bin

DLZ / ISC DHCP query

2014-03-27 Thread Marty Lee
Hi, I’m seeing some strange behaviour on a system here, and while I’m looking to find the root cause, I thought I’d post something here to see if anyone else has thoughts. (Tried searching the archives, but the web server keeps telling me that the piper mail archive page doesn’t exist.. hey ho).

Re: FreeBSD ports 9.8.7 problem with transfert to slave

2014-03-27 Thread Steven Carr
On 27 March 2014 12:31, BONNET, Frank wrote: > Since I upgraded to 9.8.7 on my two DNS the automated zones transfert from > master to slave > does not occurs automatically , I haven't change configuration files, > serials are well incremented > by a script that works for years > > BIND is install

FreeBSD ports 9.8.7 problem with transfert to slave

2014-03-27 Thread BONNET, Frank
Hello Since I upgraded to 9.8.7 on my two DNS the automated zones transfert from master to slave does not occurs automatically , I haven't change configuration files, serials are well incremented by a script that works for years BIND is installed from FreeBSD ports on the two machines, I wonder

Re: Problems with auto-dnssec maintain on BIND 9.9.5 (latest patch, FreeBSD)

2014-03-27 Thread Tony Finch
Daniel Ryslink wrote: > > At first, when the zone was not signed at all, all that sufficed was to > do "rndc loadkeys example.com", and when I later used "rndc signing > -list example.com", the keys set via > dnssec-settime as active in the keys directory were displayed. Note that `rndc signing -

Re: Problems with auto-dnssec maintain on BIND 9.9.5 (latest patch, FreeBSD)

2014-03-27 Thread Mark Andrews
In message <5333fe7a.8030...@dialtelecom.cz>, Daniel Ryslink writes: > Hello, > > I have the following zone definition included into named.conf: > > zone "example.com" in { > type master; > file "master/example.com"; > update-policy local; > auto-dnssec maintain; > key-directory "/etc/namedb/key

Problems with auto-dnssec maintain on BIND 9.9.5 (latest patch, FreeBSD)

2014-03-27 Thread Daniel Ryslink
Hello, I have the following zone definition included into named.conf: zone "example.com" in { type master; file "master/example.com"; update-policy local; auto-dnssec maintain; key-directory "/etc/namedb/keys/"; masterfile-format text; inline-signing yes; }; Keys are ready in /etc/namedb/keys/,