Re: bind918 malfunction?

2024-09-05 Thread Mark Andrews
Well from here all the IPv4 addresses for the tel.t-online.de servers are not responding. That won’t be helping things. Also the servers are generating invalid negative responses. The SOA record in the response is the QNAME rather than the owner of the zone. Also waiting an hour to retry on S

Re: bind918 malfunction?

2024-09-05 Thread Ondřej Surý
I’m on my phone, so this is a long shot, but you can try disabling the qname minimization. -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 5. 9. 2024, at 19:45, Peter wrote: >

Re: bind918 malfunction?

2024-09-05 Thread Peter
On Thu, Sep 05, 2024 at 07:05:29PM +0200, Ondřej Surý wrote: ! It’s impossible to answer your question as you haven’t provided ! absolutely no information about your problem. Perhaps if you provide ! detailed information about nature of the problem, your DNS ! configuration, and your network config

Re: Sporadic Timeouts after upgrading to bind9.20

2024-09-05 Thread Havard Eidnes via bind-users
> On our production name servers we have check every 30s if bind > is alive by sending a SOA query to bind. Today I upgraded a few > nodes from 9.18.x (x between 17 and 27) to 9.20.1 (Ubuntu 24.04 > with packages from ISC ppa). > > Since that, we have sporadic timeouts (3s). On the nodes with > mor

Re: bind918 malfunction?

2024-09-05 Thread Ondřej Surý
It’s impossible to answer your question as you haven’t provided absolutely no information about your problem. Perhaps if you provide detailed information about nature of the problem, your DNS configuration, and your network configuration, we might be able to help you. Ondrej -- Ondřej Surý — IS

bind918 malfunction?

2024-09-05 Thread Peter
I have complaints about network malfunction. From the logs I can see that a device which always regained network access within ~40 seconds, now takes 1-2 hours to recover, and this happening almost daily. There is a possible alignment between the start of the malfunction and an upgrade from 9.16 t

Re: Question about parameter settings query-source-v6 address { none; };

2024-09-05 Thread Ondřej Surý
Hi Klaus, this exact configuration is described in the KB: https://kb.isc.org/v1/docs/en/aa-00206 But my recommendation is actually to use a dual-stack proxy in front of `named -4` and use the PROXYv2 protocol to interact with named. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and y

Question about parameter settings query-source-v6 address { none; };

2024-09-05 Thread Klaus Tachtler via bind-users
Hi, is it possible to set    query-source-v6 address { none; }; I would like to make DNS requests via ipv4 and ipv6 to isc bind (incoming) from my Internal network. However, outgoing requests should only be made via ipv4. This is e.g. necessary in a scenario where a 6in4 tunnel is used for an

Re: Secure Active Directory Updates Failing on AlmaLinux 9 with ISC BIND 9.18.28

2024-09-05 Thread Nagesh Thati
Thank you all for your assistance. The issue has finally been resolved. It turns out I was running BIND in a chroot jail, and the /var/tmp folder was missing within the chroot environment. This was the cause of the AD update denials. On Tue, Aug 20, 2024 at 3:27 PM Petr Špaček wrote: > Hi Nagesh