RE: BIND and UDP tuning

2018-09-26 Thread Browne, Stuart via bind-users
> -Original Message- > From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of > Alex > Sent: Thursday, 27 September 2018 2:52 AM > To: bind-users@lists.isc.org > Subject: BIND and UDP tuning > > Hi, > > I reported a few weeks ago that I was experiencing a really high > nu

Re: NTP through DNS?

2018-09-26 Thread Chris Thompson
On Sep 24 2018, Danny Mayer wrote: [...] This is very simple to do. It does not require SRV records to implement. Note that I am only answering for the ntp reference implementation. In your domain file add entries like this: locationntp CNAME ntp1.yourdomain CNAME ntp2.yourd

BIND and UDP tuning

2018-09-26 Thread Alex
Hi, I reported a few weeks ago that I was experiencing a really high number of "SERVFAIL" messages in my bind-9.11.4-P1 system running on fedora28, and I haven't yet found a solution. This is all now running on a 165/35 cable system. I found a program named dropwatch which is showing a significan

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
Yes looks like that, also this problem started suddenly, affects all our SMG & DNS servers, so very unlikely the problem is on our end. Still Symantec "enterprise support technician" claims the problem is on our DNS servers, and as a "proof" send the chapter 4.1.1 of the RFC1035, where it is st

RE: BIND DNS problem (?)

2018-09-26 Thread Tony Finch
Jukka Pakkanen wrote: > Now got some more debug info, but does it help finding out why we get > the server failure? The DNS servers for smg.brightmail.com are broken. They drop most queries which causes all sorts of problems. Tony. -- f.anthony.n.finchhttp://dotat.at/ Humber, Thames: South

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
Now got some more debug info, but does it help finding out why we get the server failure? 26-syyskuuta-2018 15.46.33.999 client @024562471630 62.142.220.9#8179 (1d427bf569fa3b25355a5944e82b5e23.smg.ultra.brightmail.com): query failed (SERVFAIL) for 1d427bf569fa3b25355a5944e82b5e23.smg.ultra

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
Started logging named now, but don't see much debug information with these logging settings: logging { category lame-servers { null; }; category edns-disabled { null; }; category security { security_file; }; category queries { queries_file; }; category resolver { resolver_file; }; category query-

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
Started logging named now, but don't see much debug information with these logging settings: logging { category lame-servers { null; }; category edns-disabled { null; }; category security { security_file; }; category queries { queries_file; }; category resolver { resolver_file; }; category query-

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
Updated the pic, should be readable now... posting the pcap later. Jukka From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of John W. Blue via bind-users Sent: keskiviikko 26. syyskuuta 2018 9.50 To: bind-users@lists.isc.org Subject: RE: BIND DNS problem (?) I could not zoom

Re: BIND DNS problem (?)

2018-09-26 Thread Mukund Sivaraman
On Wed, Sep 26, 2018 at 07:45:46AM +, Jukka Pakkanen wrote: > > Answer authenticated: Answer/authority portion was not authenticated by the > server > Non-authenticated data: Unacceptable > This is wireshark's packet parsing output. It is not related to the SERVFAIL. > Sooo, any id

RE: BIND DNS problem (?)

2018-09-26 Thread John W. Blue via bind-users
I could not zoom in to see anything. Please post a better screenshot or better yet post the .pcap itself for download and review. John From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Jukka Pakkanen Sent: Wednesday, September 26, 2018 2:46 AM To: bind-users@lists.isc.org

BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
We are running a couple of Symantec SMG servers, and their DNS clients are configured to use your BIND 9.12.2 DNS servers. In both SMG servers we get the same DNS "server failure" error from all our DNS servers when they do some TXT queries to SMG: http://www.qnet.fi/jp/dns.png (sorry for the