Re: BIND, inline signing, include files

2017-09-27 Thread David Dowdle
Did the serial number get incremented? On Wed, 27 Sep 2017, Stefan F?rster wrote: Hello world, I was seeing a strange problem where sometimes, changes to a file included in a zone are not applied. Configuration is: - internal and external view - external zones with "auto-dnssec maintain" an

squash 'client query (cache) denied' syslog entries

2012-10-18 Thread David Dowdle
Some of my external facing nameservers are under attack, and the biggiest fallout, is the machines goign into iowait from logging all the client query denied syslog messages. note: yes, recursion is turned off on these machines. The current logging is a very vanilla logging { catego

Re: Loaded zone files query

2012-07-10 Thread David Dowdle
Actually, that gives the number of zones its supposed to be serving. if say a zone hasn't been transfered yet, it'll still show in status, (and will authoritivly answer nosuch* for it). As best as I can tell number of zones: X x=number of zones listed in named.conf + any automatically added zon

Re: Reverse zones best practices

2012-06-25 Thread David Dowdle
I strongly recommend splitting on /8 /16 and /24 boundries. With the number of zones you are talking about, doing anything else will get very confusing very quickly. If a netblock is larger than a /24, put at the top and bottom of each /24 a comment lile explaining what size it is For examp