DMARC Record issue

2015-01-04 Thread Chris Vaughan
I have been given the task of implementing DMARC in our BIND servers due the recommendation of a security audit on our systems. Whenever I create the record in the forward server, and refresh the zone, it comes out in the slave zone with escape characters inserted in the TXT record. This occurs

Re: BIND DNSSEC Guide draft

2015-01-04 Thread Timothe Litt
On 31-Dec-14 21:00, Jeremy C. Reed wrote: > ISC is seeking feedback and review for our first public draft of the > BIND DNSSEC Guide. It was written in collaboration with DeepDive > Networking. I haven't had a chance to look in detail, but a quick scan resulted in several observations that I ho

RE: can't-resolve

2015-01-04 Thread Mohammed Ejaz
yes, true the problem is from the firewall. Thanks everyone for the tremendous support. Ejaz From: Warren Kumari [mailto:war...@kumari.net] Sent: Sunday, January 4, 2015 5:09 PM To: Mohammed Ejaz Cc: Barry Margolin; comp-protocols-dns-b...@isc.org Subject: Re: can't-resolve On

Re: bind-users Digest, Vol 2011, Issue 1

2015-01-04 Thread Matus UHLAR - fantomas
On 04.01.15 14:20, Christian Kette wrote: I forgot to mention, this is actually the case The proxy has a different IP on each network. if (and only if) the clients need to use the same name for proxy... I would keep one view for each network with different IP of the same proxy, containing onl

Re: can't-resolve

2015-01-04 Thread Matus UHLAR - fantomas
On 04.01.15 08:43, Mohammed Ejaz wrote: now everything is fine once the port > 1024 opened from the network firewall. so it means not only 53 port requires to be open. BIND (and other DNS servers) uses random port for outgoing requests. som you really had firewall on the path... -- Matus UHLAR

Re: can't-resolve

2015-01-04 Thread Warren Kumari
On Sunday, January 4, 2015, Mohammed Ejaz wrote: > > Hello, all. > > now everything is fine once the port > 1024 opened from the network > firewall. Ah! You mean on the firewall that everyone kept saying existed? And that folk kept providing evidence of? Who would have thought... > so it me

Re: bind-users Digest, Vol 2011, Issue 1

2015-01-04 Thread Christian Kette
I forgot to mention, this is actually the case The proxy has a different IP on each network. 2015-01-04 13:00 GMT+01:00 : > Send bind-users mailing list submissions to > bind-users@lists.isc.org > > To subscribe or unsubscribe via the World Wide Web, visit > https://lists.isc.org