Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-10 Thread David A. Evans
s Enterprise IP/DNS Management Network Infrastructure Tools and Services From: Evan Hunt To: Stuart Henderson Cc: Tony Finch , bind-users@lists.isc.org Date: 12/09/2014 01:41 PM Subject:Re: Problem with BIND 9.10.1-P1 recursion limits Sent by:bind-users-boun...@list

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Charles Swiger
Hi-- On Dec 9, 2014, at 12:04 PM, Mike Hoskins (michoski) wrote: > Wanted to point out that (perhaps sadly) this isn't so crazypants...or at > least not uncommon. The *edge* and *aka* references speak Akamai DNS+CDN. > From my last overview, this has gotten cleaner in the latest versions of > th

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Mike Hoskins (michoski)
t; Subject: Re: Problem with BIND 9.10.1-P1 recursion limits >On Tue, Dec 09, 2014 at 05:51:58PM +, Evan Hunt wrote: >> That's unexpected. I'll see if I can reproduce it. > >Okay, I can. > >Part of the problem is the somewhat crazypants DNS configuration >of w

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Evan Hunt
On Tue, Dec 09, 2014 at 05:51:58PM +, Evan Hunt wrote: > That's unexpected. I'll see if I can reproduce it. Okay, I can. Part of the problem is the somewhat crazypants DNS configuration of www.ibm.com: $ dig +noall +answer www.ibm.com www.ibm.com.3600IN CNAME www.i

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Evan Hunt
On Tue, Dec 09, 2014 at 05:46:36PM +, Stuart Henderson wrote: > It's 5 minutes with 9.10.1-P1 as well. That's unexpected. I'll see if I can reproduce it. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ Please visit https://lists.

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Stuart Henderson
On 2014/12/09 17:37, Evan Hunt wrote: > On Tue, Dec 09, 2014 at 05:17:52PM +, Tony Finch wrote: > > Yes, I could reproduce it after flushing my cache. Had to wait five > > minutes before the queries succeeded, which seems unpleasantly long. > > I don't know where that time comes from - the ARM

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Evan Hunt
On Tue, Dec 09, 2014 at 05:17:52PM +, Tony Finch wrote: > Yes, I could reproduce it after flushing my cache. Had to wait five > minutes before the queries succeeded, which seems unpleasantly long. > I don't know where that time comes from - the ARM says the default > servfail-ttl is 10s. You'r

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Tony Finch
Evan Hunt wrote: > > However, in this case I think it's because you had an empty cache, and > sending a second query will clear the problem up. In a future release, we > may want to lift the restrictions temporarily while priming. Yes, I could reproduce it after flushing my cache. Had to wait fi

Re: Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Evan Hunt
On Tue, Dec 09, 2014 at 02:45:13PM +, Stuart Henderson wrote: > The new recursion limits (or at least the default values for them) seem > to have some problems. Simple example, if I start named for recursive > service, no forwarders, debugging enabled, and run "dig @::1 www.ibm.com a" > I get a

Problem with BIND 9.10.1-P1 recursion limits

2014-12-09 Thread Stuart Henderson
The new recursion limits (or at least the default values for them) seem to have some problems. Simple example, if I start named for recursive service, no forwarders, debugging enabled, and run "dig @::1 www.ibm.com a" I get a failure with numerous "exceeded max queries" log entries for gtld servers