Re: rndc flushname not working

2015-04-09 Thread Frank Even
On Thu, Apr 9, 2015 at 1:48 PM, Matus UHLAR - fantomas wrote: > On 09.04.15 13:25, Frank Even wrote: >> >> Is there any place I can look to get a definitive answer in what cases >> "flushname" will and will not work? > > > it will work if you have old entries in the cache. > that will NOT help you

Re: rndc flushname not working

2015-04-09 Thread Matus UHLAR - fantomas
On 09.04.15 13:25, Frank Even wrote: Is there any place I can look to get a definitive answer in what cases "flushname" will and will not work? it will work if you have old entries in the cache. that will NOT help you if any of the servers that are supposed to be authoritative for a domain will

Re: DNS anycast node monitor

2015-04-09 Thread Anand Buddhdev
On 09/04/15 16:50, Hillary Nelson wrote: Hi Hillary, > Currently we have about 20 DNS servers sit behind two pairs of F5 LTM on > campus, the two pairs of F5s using router injection for DNS virtual > addresses. This setup is costly and we are trying to use direct anycast > between router and serv

Re: rndc flushname not working

2015-04-09 Thread Frank Even
Is there any place I can look to get a definitive answer in what cases "flushname" will and will not work? I've been digging around in lists and docs and can't seem to find any definitive answers. I've been having odd troubles clearing a name from a cache and after even clearing the name and the

Re: configured bind 9.10.1 as slave gettting data in binary form

2015-04-09 Thread Alan Clegg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 > Or you can allow your slave files to remain in binary format (it > gives you a roughly factor-4 speedup in loading the files, which > can be significant with large zones). When you want to look at the > text version, convert them: > > $ named-ch

Re: DNS anycast node monitor

2015-04-09 Thread Eli Heady
We're considering doing something similar, but have nothing in the way of scripts to offer. I'm curious what you mean by 'router injection for DNS virtual addresses'. Off topic for this list, sorry, but are you meaning that you're currently using dynamic routing (BGP/OSPF/RIP) in the F5 TMM? This

Re: Native pkcs#11 and auto-dnssec feature

2015-04-09 Thread Alan Clegg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 4/9/15 2:58 AM, Catalin Leanca wrote: > "If the label contains a pin-source field, tools using the > generated key files will be able to use the HSM for signing and > other operations without any need for an operator to manually enter > a PIN." W

DNS anycast node monitor

2015-04-09 Thread Hillary Nelson
Currently we have about 20 DNS servers sit behind two pairs of F5 LTM on campus, the two pairs of F5s using router injection for DNS virtual addresses. This setup is costly and we are trying to use direct anycast between router and server instead, with quagga and bgp. The decision of advertise/wit

Re: on TTL expiry BIND sends 'ANY' query, gets back 'NOANSWER'

2015-04-09 Thread Phil Mayers
On 08/04/15 22:00, Chuck Anderson wrote: No, you are right. My filtered view of the packet capture was missing the fact that another unrelated client did an 'ANY' query. I found it in the query log. BIND 9.10 implements prefresh, but I'm on 9.8.2. Oops just saw this, disregard my other ema

Re: on TTL expiry BIND sends 'ANY' query, gets back 'NOANSWER'

2015-04-09 Thread Phil Mayers
On 08/04/15 20:25, Chuck Anderson wrote: My questions are, what is at fault here? Is it a BIND bug to expect It all sounds really odd. In particular, if there is no recursive client triggering them, and no prefetch, where are these ANY/A queries on TTL expiry coming from? Are you certain