Re: timeouts and negative caching

2015-06-11 Thread Gerd v. Egidy
Hi Tony, > Look at the lame-ttl option. (though I think the behaviour is more > complicated than the documentation implies) I can report that lame-ttl doesn't help either, the timeout ttl stays at 300 secs. >From reading the manual it seems to me that a "lame server" is something different th

Re: timeouts and negative caching

2015-06-11 Thread Gerd v. Egidy
Hi Mike, On Thursday 11 June 2015 14:37:11 you wrote: > I'm not sure if BIND has a separate tunable for the "timeout vs true > negative answer" scenario you seem to describe, but have you tried setting > max-ncache-ttl very low to see if it affects this? just tried it: max-ncache-ttl doesn't seem

Re: timeouts and negative caching

2015-06-11 Thread Tony Finch
Mike Hoskins (michoski) wrote: > I'm not sure if BIND has a separate tunable for the "timeout vs true > negative answer" scenario you seem to describe, but have you tried setting > max-ncache-ttl very low to see if it affects this? Look at the lame-ttl option. (though I think the behaviour is mo

Re: timeouts and negative caching

2015-06-11 Thread Mike Hoskins (michoski)
I'm not sure if BIND has a separate tunable for the "timeout vs true negative answer" scenario you seem to describe, but have you tried setting max-ncache-ttl very low to see if it affects this? On 6/11/15, 9:27 AM, "Gerd v. Egidy" wrote: >Hi, > >I've got a bind running as recursive resolver be

Re: different answers for different users - are views my only option?

2015-06-11 Thread Warren Kumari
On Thu, Jun 11, 2015 at 10:11 AM, Tony Finch wrote: > McDonald, Dan wrote: > >> Is there a way to use RPZ to return different answers depending on the >> ip address of the querying box? > > Yes in 9.10 but not in 9.9. However I think rpz-client-ip triggers rewrite > all queries from metching clie

Re: different answers for different users - are views my only option?

2015-06-11 Thread Tony Finch
McDonald, Dan wrote: > Is there a way to use RPZ to return different answers depending on the > ip address of the querying box? Yes in 9.10 but not in 9.9. However I think rpz-client-ip triggers rewrite all queries from metching clients, so it probably isn't what you want. (To be honest, I thin

timeouts and negative caching

2015-06-11 Thread Gerd v. Egidy
Hi, I've got a bind running as recursive resolver behind a thin internet line. When the line is clogged, requests sometimes time out. When the dns client retries the query, bind usually retries the request and eventually succeeds. So far so good. But now I sometimes see that bind does not retr

different answers for different users - are views my only option?

2015-06-11 Thread McDonald, Dan
We have an application that that has application servers burried deep behind a few layers of reverse proxies and load balancers, but has a hard-coded server address in a returned java applet. To allow the java applets to work, someone here started deploying host files containing the app servers

Re: Set up a recursive servers to provide different data (liumingxing)

2015-06-11 Thread liumingxing
RPZ is ok. Thanks :) Mingxing CNNIC EMAIL:liumingx...@cnnic.cn From: Bob McDonald Date: 2015-06-10 21:34 To: bind-users Subject: Set up a recursive servers to provide different data (liumingxing) You could also use RPZ to provide answers for only the hosts in question. This would return a spec