I'm not sure, is it right for the management of zone files, with both dynamic
update and editting by hand?
bind-users mailing list
I found a strange problem.
We have a zone in Bind, for example, abc.com
We designate a subzone of it to another dns server, for eaxmple, F5's 3DNS.
The corresponding RR in Bind is:
games.abc.com. IN NS 3600 ns1.example.com.
games.abc.com. IN NS 3600 ns2.example.com.
Bind's setup
Thanks a lot Matthew.
> CNAME records are special. You can't have any other
> records for a label
> where you have a CNAME record (well, with the exception of
> RRSIG records
> if you're using DNSSEC). This is covered in great
> detail in any
> introductory text on DNS.
> The principle rea
--- On Tue, 23/11/10, Matus UHLAR - fantomas wrote:
> From: Matus UHLAR - fantomas
> Subject: Re: can @ be CNAME?
> To: bind-users@lists.isc.org
> Received: Tuesday, 23 November, 2010, 3:58 PM
> On 23.11.10 15:50, Tech W. wrote:
> > can I set @ to a cname type? like:
can I set @ to a cname type? like:
@ IN CNAME www.example.com.
bind-users mailing list
Thanks a lot.
That looks much helpful for me.
--- On Wed, 17/11/10, Josh Miller wrote:
> From: Josh Miller
> Subject: Re: MySQL BIND SDB
> To: bind-users@lists.isc.org
> Received: Wednesday, 17 November, 2010, 9:38 AM
> On 11/15/2010 10:58 PM, Tech W.
> wrote:
> > Is
Is mysql Bind SDB suitable for a production application?
We have many dozens of domains in the bind servers, what's the best way to
maintain the zones and records?
bind-users mailing list
--- On Fri, 15/10/10, Mark Andrews wrote:
> From: Mark Andrews
> Subject: Re: No cache for NS RR in public DNS
> To: "Tech W."
> Cc: bind-us...@isc.org
> Received: Friday, 15 October, 2010, 9:21 PM
> In message <811222.51900...@web15706.mail.cnb.yahoo.c
like this domain:
I can't get its NS RR in public DNS:
dig blogchina.org ns @
get nothing.
But it does work correctly.
for example, query the record:
dig udb.yy.blogchina.org
How to setup Bind for this?
I have a question about the query process of local dns cache to remote servers.
When my local dns cache want to find the A record for a domain name, for
example, www.example.com
If the A record doesn't exist in its cache, but example.com's NS records are
Thus the dns cache will que
- Original Message
> From: Alan Clegg
> To: bind-users@lists.isc.org
> Sent: Fri, 15 January, 2010 11:37:58 AM
> Subject: Re: a question on bind cache
> You could monitor your services and then use dynamic DNS to change
> resource records based on the results, but it's not the bes
- Original Message
> From: Kevin Darcy
> To: bind-users@lists.isc.org
> Sent: Thu, 14 January, 2010 11:42:32 PM
> Subject: Re: a question on bind cache
> The highest incentive, and the optimal strategy, is for content *owners*
> to manage this, not *consumers*.
> http://lmgtfy.
We have been facing this problem, sometime the original server was down, but
Bind didn't know it, and still answered clients with the dead IP.
Or sometime an external domain name has two or more IPs, accessing to part of
them is fast, but accessing to another part is slow.
So, do you thi
--- On Fri, 4/12/09, Kevin Darcy wrote:
> From: Kevin Darcy
> Subject: Re: parent dns answers the ARR of child dns
> To: bind-users@lists.isc.org
> Received: Friday, 4 December, 2009, 1:56 AM
> Not only that, but DNS.gduf.edu.cn is
> performing recursion, while not
> setting RA in, and not co
Firstly thanks for any helps I have got on this list for our DNS setup in
university environment.
Now I meet another problem, please see this dig:
# dig smartip.gduf.edu.cn ns +short
That means smartip.gduf.edu.cn is a zone whose NS is dtone1.gduf.edu.cn.
I have se
--- On Mon, 3/8/09, Matus UHLAR - fantomas wrote:
> Many people consider that a bad idea. the DNS is used by
> many applications
> in many manners and providing false answers can break them
> in many ways.
Here the primary ISP CN Telecom does do DNS hijack, though I hate this.
--- On Tue, 28/7/09, Stephane Bortzmeyer wrote:
> > what's the use of bind's tcp port 53?
> DNS requests and responses.
oh, I was always thinking dns requests and responses are going with udp
protocal. under what condition it uses tcp protocal?
ost is not authorized to connect,
* the clocks are not syncronized, or
* the key is invalid.
bind version:
# sbin/named -v
BIND 9.6.0-P1
Please help, thanks.
--- On Thu, 16/7/09, Evan Hunt wrote:
> From: Evan Hunt
> Subject: Re: about allow-update
> To: "Te
what's the use of bind's tcp port 53?
is it used for dns update and zone transfer or something else?
If I have not been using dynamic update and transfer, can I block tcp port 53
using a firewall?
--- On Tue, 21/7/09, Mark Andrews wrote:
> From: Mark Andrews
> Subject: Re: about cache nonexist record
> To: "Tech W."
> Cc: bind-users@lists.isc.org
> Received: Tuesday, 21 July, 2009, 8:01 AM
> In message <950.42549...@web15608.mail.cnb.yahoo.com>
I have Bind-9.6.1 running on our university environment, have been using
dynamic update.
My question is, when other DNS query my named for a record, for example
test.example.com, but this record doesn't exist. How long time will the remote
DNS cache this nonexist record?
I found the p
--- On Sat, 18/7/09, Mark Andrews wrote:
> From: Mark Andrews
> Subject: Re: no glue A record in child domain
> To: "Tech W."
> Cc: bind-users@lists.isc.org
> Received: Saturday, 18 July, 2009, 10:22 PM
> In message <961314.13824...@web15606.mail.
Hello gurus,
Say I have this glue record in parent's DNS:
child.example.com. IN NS ns.child.example.com.
ns.child.example.com. IN A
Then in child's zone file, I don't include the A record for
What will be happened? Does it affect client's query to othe
Dear list,
Currently I'm using TSIG key for dynamic update auth.
allow-update {key "mykey";};
Besides TSIG key, I want to limit the source address also.
That's to say, I want the given address with specified key to execute the
update only.
How can I do it? Is this syntax correct?
I know how to dynamic update on a basic named config.
but my named has views setup, how to dynamic update the records to each view?
Can you point to me some resources? Thanks.
Need a Holiday? Win a $10,000 Holiday of your choice. Enter
Is it possible to set weight for records?
for example,I have these two A records:
wwwIN A
But I want take the weight of 75%, and take the
weight of 25%. That means, when clients query for www.domain.com, 1.100 h
What will be happened if a MX is an numeric IP?
for example,
# dig vip.online2.sh.cn mx +short
Need a Holiday? Win a $10,000 Holiday of your choice. Enter
--- On Mon, 18/5/09, Mark Andrews wrote:
> From: Mark Andrews
> Subject: Re: dig info
> To: "Tech W."
> Cc: bind-users@lists.isc.org
> Received: Monday, 18 May, 2009, 10:35 PM
> In message <980168.77226...@web15605.mail.cnb.yahoo.com>,
> "Tech
, 0.1);
(4) run both shell and perl scripts, and watch the results output of perl
After tested for some time (ie, 10 minutes), I got nothing from perl script's
So I assume that when named is reloading, it doesn't affect user's query.
Am I right? thanks for any
Just asked this question again, b/c it's not easy to test...
When named is reloading with 'rndc reload' command, client's query is coming
in, what will be happened? Will client's request be dropped?
Need a Holiday? Win a $10,000 Holiday of your choice. Enter
Sometime I dig a domain name, it returns the results below:
;; reply from unexpected source:, expected
;; reply from unexpected source:, expected
;; reply from unexpected source:, expected
--- On Wed, 13/5/09, Stephane Bortzmeyer wrote:
> Remove the allow-update directive.
But she is running the windows DNS server not Bind..
Need a Holiday? Win a $10,000 Holiday of your choice. Enter
I have a bind host installed. It has two public IP addresses.
I want to give two NS records for my domain, each NS take each of the IP set in
the host.
more details, the host has two IPs:
surely policy reoute for two nics was enabled.
I add these info into na
--- On Wed, 13/5/09, Kal Feher wrote:
> From: Kal Feher
> Subject: Re: glue record
> To: bind-users@lists.isc.org
> Received: Wednesday, 13 May, 2009, 5:34 PM
> Your domain is still broken. You need
> to remove the NS record for your
> internal host.
I have requested the hostmaster, who
Oh yes, I have got it. Thanks.
--- On Wed, 13/5/09, Stephane Bortzmeyer wrote:
> From: Stephane Bortzmeyer
> Subject: Re: glue record
> To: "Tech W."
> Cc: "Stephane Bortzmeyer" , bind-users@lists.isc.org
> Received: Wednesday, 13 May, 2009, 3:40 PM
--- On Wed, 13/5/09, Stephane Bortzmeyer wrote:
> Glue was sent back since wanadoo.fr's name servers are
> under
> wanadoo.fr .
Ok please see dig info below.
if I understand for it correctly, gdpu.cn is not under b.dns.cn, why b.dns.cn
returns glues?
# dig gdpu.cn ns @B.DNS.cn
I'm just not very sure, what's the usage for a glue record?
When an upper DNS returns a domain's authorised DNS server, will it also
returns the authorised DNS server's IP address? So glue record works as this
Thanks for any replies.
Need a Holiday? Win a $10,000 Holiday
Thanks Kal. That let things be clear.
--- On Mon, 11/5/09, Kal Feher wrote:
> Note that the reason your queries fail is because name
> servers are supposed
> to assume that the apex of the zone contains the most
> correct data.
> Therefore if the 2 name servers to which this zone is
> delega
Firstly the DNS serveres for that domain is not mastered by me.
I got the NS dig info as below.
You can see, if I specify another public DNS (, the results can
be fetched. If I don't specify a DNS (use the default one of my
ISP), dig gets nothing.
So I'm really
For this domain, gdpu.cn, I tried to find its ns record:
dig gdpu.cn ns
with no results.
But I can dig its www record as below.
why this happened? I can't understand entirely..
# dig www.gdpu.cn
; <<>> DiG 9.5.0-P2 <<>> www.gdpu.cn
;; global options: printcmd
;; Got answer:
When named is reloading (rndc reload) and at this time the query request is
coming, what will be happened? Will this query be rejected? Thanks.
bind-users mailing list
Thanks for chris, barry and all.
--- On Tue, 14/4/09, Barry Margolin wrote:
> There's a special exception made for "glue" records, since
> they're
> needed to prevent an infinite recursion. The parent
> zone will include
> this A record.
Enjoy a safer web experience. Upgrade to
--- On Tue, 14/4/09, Chris Buxton wrote:
> From: Chris Buxton
> Subject: Re: about resolving on a child zone
> In this case, the answer is that your main zone
> (example.com) will have an error, because it will have an A
> record below the "bottom" of the zone that is not a glue
> record.
I have the domain saying it's example.com.
I defined a NS (and its A rcd) as below:
my.example.com. IN NS mydns.example.com.
mydns.example.com. IN A
Also I added this A record in both main DNS and the child zone's DNS
www.my.example.com. IN A
--- On Sun, 12/4/09, Gregory Hicks wrote:
> From: Gregory Hicks
> Subject: Re: help on strange dig info
> To: bind-users@lists.isc.org, tech...@yahoo.com.cn
> Received: Sunday, 12 April, 2009, 3:33 PM
> > I digged a domain name as below:
> >
> > r...@dev1:~# dig www.csfunds.com.cn
> >
I digged a domain name as below:
r...@dev1:~# dig www.csfunds.com.cn
; <<>> DiG 9.5.0-P2 <<>> www.csfunds.com.cn
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23283
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 2, ADDITIONAL: 0
--- On Sun, 12/4/09, Chris Buxton wrote:
> From: Chris Buxton
> Subject: Re: about ns record in child domain
> To: "Tech W."
> Cc: bind-users@lists.isc.org
> Received: Sunday, 12 April, 2009, 11:04 AM
> On Apr 11, 2009, at 7:42 PM, Tech W.
> wrote:
> >
I have a domain said example.com.
in example.com's main DNS I added a NS record:
cdn.example.com. IN NS otherdns.example.com.
otherdns.example.com. IN A
Then in DNS of otherdns.example.com, I set something in named.conf like:
zone "cdn.example.com" {
48 matches
Mail list logo