Re: dnssec validation issue

2015-06-19 Thread Jaap Akkerhuis
Eray Aslan writes: > On Thu, Jun 18, 2015 at 07:26:28PM -0700, Carl Byington wrote: > > On Fri, 2015-06-19 at 11:10 +1000, Mark Andrews wrote: > > > To use the keys in "/etc/named.iscdlv.key" set "dnssec-validation > > > auto;" > > New centos rpms at http://www.five-ten-sg.com/mapper/bind wi

Re: file descriptor exceeds limit

2015-06-19 Thread Matus UHLAR - fantomas
On 6/18/15, 7:09 PM, "Stuart Browne" wrote: Just wondering. You mention you're using RHEL6; are you also getting messages in 'dmesg' about connection tracking tables being full? You may need some 'NOTRACK' rules in your iptables. On 18.06.15 23:11, Mike Hoskins (michoski) wrote: Just follow

Re: dnssec validation issue

2015-06-19 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Fri, 2015-06-19 at 05:58 +, Eray Aslan wrote: > With the root zone and most TLDs signed, I do not think it makes sense > to use DLV anymore. While a typical DNSSEC resolver configuration has > DLV enabled, I personally make the effort to disabl

Re: file descriptor exceeds limit

2015-06-19 Thread Mike Hoskins (michoski)
On 6/19/15, 5:07 AM, "bind-users-boun...@lists.isc.org on behalf of Matus UHLAR - fantomas" wrote: >>On 6/18/15, 7:09 PM, "Stuart Browne" >>wrote: >>>Just wondering. You mention you're using RHEL6; are you also getting >>>messages in 'dmesg' about connection tracking tables being full? You >>

Re: file descriptor exceeds limit

2015-06-19 Thread Reindl Harald
Am 19.06.2015 um 18:44 schrieb Mike Hoskins (michoski): I suppose the only way to avoid any "intermediate" firewalls would be to place everything you run on a LAN segment hanging directly off your router/Internet drop with host based firewalls well, if the router is from Cisco and has NAt ena

"#service named restart" fails with a weird message

2015-06-19 Thread Samad Agha
Hey Gurus, When I try to restart named, it fails with the following message: [root@new-dns2 ~]# service named restart Stopping named:[ OK ] Starting named: Error in named configuration: /etc/named.conf:3: missing ';' before '}' /etc/named.conf:11: miss

Re: "#service named restart" fails with a weird message

2015-06-19 Thread Jeremy C. Reed
On Fri, 19 Jun 2015, Samad Agha wrote: > Error in named configuration: > /etc/named.conf:3: missing ';' before '}' Look on line 3 > /etc/named.conf:11: missing ';' before '}' Look on line 11 > options { > directory "/var/named"; >     allow-recursion {207.151.36.0/24; 206.117.117.

Re: "#service named restart" fails with a weird message

2015-06-19 Thread John Miller
Semicolons! You need one for the second ip range in your list, and you need one after the zone file for your localhost zone. The error message really does tell you what you need in this case ;-) The config you pasted only has nine lines, so I'm assuming that the last error really is on line 8/9

Re: file descriptor exceeds limit

2015-06-19 Thread Mike Hoskins (michoski)
On 6/19/15, 1:16 PM, "bind-users-boun...@lists.isc.org on behalf of Reindl Harald" wrote: >Am 19.06.2015 um 18:44 schrieb Mike Hoskins (michoski): >> I suppose the only way to avoid any "intermediate" firewalls would be to >> place everything you run on a LAN segment hanging directly off your >>

Re: file descriptor exceeds limit

2015-06-19 Thread /dev/rob0
On Thu, Jun 18, 2015 at 11:11:16PM +, Mike Hoskins (michoski) wrote: > On 6/18/15, 7:09 PM, "Stuart Browne" > wrote: > > >Just wondering. You mention you're using RHEL6; are you also > >getting messages in 'dmesg' about connection tracking tables being > >full? You may need some 'NOTR

Re: file descriptor exceeds limit

2015-06-19 Thread /dev/rob0
On Fri, Jun 19, 2015 at 02:55:23PM -0500, I wrote: > On Thu, Jun 18, 2015 at 11:11:16PM +, >Mike Hoskins (michoski) wrote: snip > Note that connection tracking can be a problem upstream as well, > for the same reasons as described in the article. I would still > turn off conntrack for UD

Re: file descriptor exceeds limit

2015-06-19 Thread Mike Hoskins (michoski)
On 6/19/15, 4:07 PM, "bind-users-boun...@lists.isc.org on behalf of /dev/rob0" wrote: >On Fri, Jun 19, 2015 at 02:55:23PM -0500, I wrote: >> On Thu, Jun 18, 2015 at 11:11:16PM +, >>Mike Hoskins (michoski) wrote: >snip >> Note that connection tracking can be a problem upstream as well, >>