Re: NOAA.GOV domain not working

2017-09-19 Thread Scott Morizot
+1 On Mon, Sep 18, 2017 at 8:58 PM, Mark Andrews wrote: > We really should make all the root and TLD servers return maximal > EDNS answers (pad to the advertised EDNS UDP size). This would > create a little short term pain by exposing all the broken firewalls > which would then get fixed or the

RE: NOAA.GOV domain not working

2017-09-19 Thread Levesque, Ricky (SNB)
users@lists.isc.org Subject: Re: NOAA.GOV domain not working I actually expect that you problem is your firewall in that it is dropping fragmented UDP responses. The UDP responses for www.nhc.noaa.gov are large. They do not fit in a single ethernet frame. Compare the following two qu

Re: NOAA.GOV domain not working

2017-09-18 Thread Mark Andrews
In message , John Miller writes: > Hi Ricky, > > Try running a "dig +trace www.nhc.noaa.gov," then query each record in > the chain and see which one's slow to respond. I don't see anything > crazy in your named.conf. Something you didn't mention: does clearing > cache make a difference? W

Re: NOAA.GOV domain not working

2017-09-18 Thread Mark Andrews
In message <36f8dd297fd5504aa37968ada5ba93eb01178c2...@gnbexmb8pb.gnb.ca>, "Levesque, Ricky (SNB)" writes: > Thanks Warren, > I can query all the noaa.gov name servers without issues, and the replies > are fast (sub 100ms) Remember nameservers ask questions with different options set to DiG's de

Re: NOAA.GOV domain not working

2017-09-18 Thread Mark Andrews
Kpyp/JHSM6hfeWKoAW3P0IaEeY+nYm91jdZ1Z214sWpiGmjvtE46KV4 > oVwvwnhyMjqI6gIZ9tTmm67iKz5E4UF524d/liZL9RMqSoy5uL94VUSm tSs= > ;; Received 483 bytes from 69.36.157.30#53(a.gov-servers.net) in 49 ms > > ;; connection timed out; no servers could be reached > > > > > -Original Messa

Re: NOAA.GOV domain not working

2017-09-18 Thread Sten Carlsen
aa.gov name servers without issues, and the replies are > fast (sub 100ms) > > -Original Message- > From: Warren Kumari [mailto:war...@kumari.net] > Sent: September 18, 2017 12:06 PM > To: Levesque, Ricky (SNB) > Cc: John Miller ; bind-users@lists.isc.org > Subje

RE: NOAA.GOV domain not working

2017-09-18 Thread Levesque, Ricky (SNB)
: Re: NOAA.GOV domain not working On Mon, Sep 18, 2017 at 10:40 AM, Levesque, Ricky (SNB) wrote: > Thank you for your reply, > When I notice too many failed queries from this domain name > (www.nhc.noaa.gov) restarting the service or clearing the cache (rndc > reload), seems to allo

Re: NOAA.GOV domain not working

2017-09-18 Thread John Miller
UUOtQnMJgAZQAPS0J259CtXri0WyuDnJsdA5Glqt7FUAnvOFXNCEO8K6 > 0Kpyp/JHSM6hfeWKoAW3P0IaEeY+nYm91jdZ1Z214sWpiGmjvtE46KV4 > oVwvwnhyMjqI6gIZ9tTmm67iKz5E4UF524d/liZL9RMqSoy5uL94VUSm tSs= > ;; Received 483 bytes from 69.36.157.30#53(a.gov-servers.net) in 49 ms > > ;; connection timed out;

Re: NOAA.GOV domain not working

2017-09-18 Thread Warren Kumari
unds like you cannot reach the noaa.gov nameservers (or they cannot reach you!) W > > > -Original Message- > From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of John > Miller > Sent: September 18, 2017 11:03 AM > Cc: bind-users@lists.isc.org > S

RE: NOAA.GOV domain not working

2017-09-18 Thread Levesque, Ricky (SNB)
bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of John Miller Sent: September 18, 2017 11:03 AM Cc: bind-users@lists.isc.org Subject: Re: NOAA.GOV domain not working Hi Ricky, Try running a "dig +trace www.nhc.noaa.gov," then query each record in the chain and see which one'

Re: NOAA.GOV domain not working

2017-09-18 Thread John Miller
Hi Ricky, Try running a "dig +trace www.nhc.noaa.gov," then query each record in the chain and see which one's slow to respond. I don't see anything crazy in your named.conf. Something you didn't mention: does clearing cache make a difference? John -- John Miller Systems Engineer Brandeis Univ

NOAA.GOV domain not working

2017-09-18 Thread Levesque, Ricky (SNB)
Good day, I've been having an interesting issue with BIND and wondering if anyone has had this before or knows how to fix it. The issue is, I have 2 recursive/caching DNS servers running BIND 9.9.4-RedHat-9.9.4-51.el7, which are slow to query for this particular domain. Noaa.gov (as well as its