Re: RRL probably not useful for DNS IP blacklists, was Re: New Versions of BIND are available (9.9.4, 9.8.6, and 9.6-ESV-R10)

2013-09-24 Thread Tony Finch
Simon Forster wrote: > > Excellent info. Thank you. What's the specs of the machine you're testing on? An old-ish Dell Optiplex 760, Core 2 Duo, 3.16 GHz, 4GB RAM. Tony. -- f.anthony.n.finchhttp://dotat.at/ Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first. Rough,

Re: RRL probably not useful for DNS IP blacklists,

2013-09-24 Thread Tony Finch
Vernon Schryver wrote: > > It's convenient that with binary zone files and the dynamic update > protocol, loading from text (or signing a whole zone) is not something > you need to do every hour on the hour. Right. Timings from named-checkzone give a rough idea of a worst-case cold start. I ran

Re: RRL probably not useful for DNS IP blacklists,

2013-09-24 Thread Noel Butler
On Mon, 2013-09-23 at 19:21 +, Vernon Schryver wrote: > > > As a matter of interest, if one had a DNSBL with 5.5 million entries > > > (i.e. 5.5 million IPs): > > > > > > 1) What needs to be done to rewrite that to a BIND zone? > > > 2) What sort of machine would be required to load that zone

Re: RRL probably not useful for DNS IP blacklists,

2013-09-24 Thread Vernon Schryver
> From: Noel Butler > We used to run our int bl on bind, it was a resource hog compared to > rbldnsd > But there is no way in hell, I'd run rbldnsd on anything else other > than a BL, > > IMO, they are both designed to do different things, and they both do > their own thing, much better than the

Looking for info about BIND support for International Domain Names

2013-09-24 Thread M. Meadows
Wondering about IDN support for BIND. UTF-8 character set? Searched for these in this forum and didn't find much. May have missed it. Anything helpful already out there for review? Thanks! Martin Meadows Indianapolis, IN _

Re: Looking for info about BIND support for International Domain Names

2013-09-24 Thread staticsafe
On 9/24/2013 09:45, M. Meadows wrote: Wondering about IDN support for BIND. UTF-8 character set? Searched for these in this forum and didn't find much. May have missed it. Anything helpful already out there for review? Thanks! Martin Meadows Indianapolis, IN Came upon on this thread from 2010

Occasional SERVFAILs from "dig NS iq."

2013-09-24 Thread Chris Thompson
I have noticed that I get occasional (fast) SERVFAIL responses from "dig NS iq.", e.g. $ dig ns iq. ; <<>> DiG 9.9.4 <<>> ns iq. ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 7919 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

Re: Looking for info about BIND support for International Domain Names

2013-09-24 Thread Jeff Reasoner
You'll need libidn and libiconv. IDN code is in the bind-9.x tarball in contrib/idn/idnkit-1.0-src You need to include the --with-idn=yes and --with-iconv=yes options. I recall having had to configure and build idn first, and then build bind including the options in each. Jeff R. On Tue, 2013-

Re: Occasional SERVFAILs from "dig NS iq."

2013-09-24 Thread Tony Finch
Chris Thompson wrote: > I have noticed that I get occasional (fast) SERVFAIL responses from > "dig NS iq.", e.g. > > "iq" is partially signed, in the sense that some of its nameservers > deliver a signed version, and some an unsigned one, but I don't see > how that leads to the effect observed.

statistics file and views

2013-09-24 Thread Sébastien WENSKE
Hi List, I have the feeling that something is wrong with my stats, external view is empty. Do I set something other in addition to "statistics-file "/var/cache/bind/named.stats";" ? Many thanks. Sebastien W root@dns01:/var/cache/bind# cat named.stats +++ Statistics Dump +++ (1380038757) ++ I

Re: Occasional SERVFAILs from "dig NS iq."

2013-09-24 Thread Chris Thompson
On Sep 24 2013, Tony Finch wrote: Chris Thompson wrote: I have noticed that I get occasional (fast) SERVFAIL responses from "dig NS iq.", e.g. "iq" is partially signed, in the sense that some of its nameservers deliver a signed version, and some an unsigned one, but I don't see how that lead

Re: statistics file and views

2013-09-24 Thread Warren Kumari
Probably a stupid question, but are you sure that any queries are matching / hitting your external view? W On Sep 24, 2013, at 9:06 AM, Sébastien WENSKE wrote: > Hi List, > > I have the feeling that something is wrong with my stats, external view is > empty. > > Do I set something other in a

Re: statistics file and views

2013-09-24 Thread Sébastien WENSKE
Yes, I can see the queries in the log file. Warren Kumari a écrit : Probably a stupid question, but are you sure that any queries are matching / hitting your external view? W On Sep 24, 2013, at 9:06 AM, Sébastien WENSKE wrote: > Hi List, > > I have the feeling that something is wrong with

How can I determine if 9.9.4 bind named executable was built with --enable-rrl?

2013-09-24 Thread Red Cricket
Hi, I understand to be able to use rate-limiting with BIND 9.9.4 it needed to have been built with this "./configure --enable-rrl" configure command. But what if I am not the person that builds named? How can I determine if it was built with rate-limiting? I have tried isc-config.sh and rndc sta

Re: How can I determine if 9.9.4 bind named executable was built with --enable-rrl?

2013-09-24 Thread Phil Mayers
On 24/09/13 18:06, Red Cricket wrote: Hi, I understand to be able to use rate-limiting with BIND 9.9.4 it needed to have been built with this "./configure --enable-rrl" configure command. But what if I am not the person that builds named? How can I determine if it was built with rate-limiting?

Re: How can I determine if 9.9.4 bind named executable was built with --enable-rrl?

2013-09-24 Thread Tony Finch
Red Cricket wrote: > How can I determine if it was built with rate-limiting? named -V Tony. -- f.anthony.n.finchhttp://dotat.at/ Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first. Rough, becoming slight or moderate. Showers, rain at first. Moderate or good, occasi

RE: statistics file and views

2013-09-24 Thread Sébastien WENSKE
Some logs: root@dns01:/var/log/bind# grep "view external" named.log 21-Sep-2013 21:25:50.252 queries: client 107.20.81.55#32861: view external: query: th2rdns01.at-inf 21-Sep-2013 21:25:50.253 queries: client 107.20.81.55#48727: view external: query: dns01.hq0.fo.at- 21-Sep-2013 21:26:08.589 que

Re: RRL probably not useful for DNS IP blacklists,

2013-09-24 Thread Noel Butler
On Tue, 2013-09-24 at 13:40 +, Vernon Schryver wrote: > > From: Noel Butler > > > We used to run our int bl on bind, it was a resource hog compared to > > rbldnsd > > But there is no way in hell, I'd run rbldnsd on anything else other > > than a BL, > > > > IMO, they are both designed to do

Re: RRL probably not useful for DNS IP blacklists,

2013-09-24 Thread Vernon Schryver
> From: Noel Butler > you clearly have a bias set-in-concrete mindset about rbldnsd, maybe you > and its author hate each others guts, I dunno, dont care, our decision > is based on real world live usages, tests, and experiences, for over ten > years of using rbldnsd and twenty with bind, so Ver

Re: statistics file and views

2013-09-24 Thread Mark Andrews
In message <6b2bb1e5900044db85cb787fae793...@swsexch02.sw-servers.local>, =?iso -8859-1?Q?S=E9bastien_WENSKE?= writes: > Some logs: > > root@dns01:/var/log/bind# grep "view external" named.log > 21-Sep-2013 21:25:50.252 queries: client 107.20.81.55#32861: view > external: query: th2rdns01.at-inf >