troubleshooting slow queries?

2021-05-26 Thread M.
Hi! Are there any best practices on troubleshooting slow queries? ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact

Re: 9.18 BIND not resolving .gov.bd site

2023-10-30 Thread Marco M.
Am 30.10.2023 um 12:25:32 Uhr schrieb Mosharaf Hossain: > mofa.gov.bd.86400 IN NS ns1.bcc.gov.bd. > mofa.gov.bd.86400 IN NS ns2.bcc.gov.bd. > couldn't get address for 'ns1.bcc.gov.bd': not found > couldn't get address for 'ns2.bcc.gov.bd': not found

Re: DNS NXDOMAIN flood

2023-11-01 Thread Marco M.
Am 02.11.2023 um 12:02:00 Uhr schrieb Mosharaf Hossain: > We are receiving the traffic form random IP addresses to DNS servers. Even when those IP addresses change, can you verify in any way that those are not spoofed, so the traffic originates rom that networks? -- Visit https://lists.isc.org/m

Re: Help about DNS documentation

2023-11-03 Thread Marco M.
Am 03.11.2023 um 15:20:50 Uhr schrieb Amaury Van Pevenaeyge: > Hello everyone, > > I'm currently a final year Master's student at the Free University of > Brussels. As part of my Master's thesis, I have to implement a DNS > amplification scenario within a Cyber Range. However, before > achieving

Re: How should I configure internal and external DNS servers

2023-11-03 Thread Marco M.
Am 03.11.2023 um 15:51:32 Uhr schrieb Nick Howitt via bind-users: > As this site is externally accessible as well, we also have to put an > identical entry in bind-external so we end up having many identical > entries in bind-internal and bind-external. It seems they people who set that up didn't

Re: How should I configure internal and external DNS servers

2023-11-03 Thread Marco M.
Am 03.11.2023 um 17:48:32 Uhr schrieb Nick Howitt via bind-users: > My problem is the use of external IP's duplicated between the > internal and external masters for some IPs/FQDNs which I want to get > rid of. Implement IPv6 and get rid of the old IPv4 technology for internal communication. It

Re: How should I configure internal and external DNS servers

2023-11-03 Thread Marco M.
Am 03.11.2023 um 17:58:51 Uhr schrieb Nick Howitt via bind-users: > On 03/11/2023 17:54, Marco M. wrote: > > Am 03.11.2023 um 17:48:32 Uhr schrieb Nick Howitt via bind-users: > > > >> My problem is the use of external IP's duplicated between the > >> inte

Re: How should I configure internal and external DNS servers

2023-11-03 Thread Marco M.
Am 03.11.2023 um 19:15:45 Uhr schrieb Nick Howitt via bind-users: > You are preaching to the converted, but we have a huge mix of SLES > 11, Ubuntu 16, 18, 20 and 22 machines + Windows Server 2016. Getting > them all current is a long term project and it has to go through all > sorts of customer a

Re: How should I configure internal and external DNS servers

2023-11-03 Thread Marco M.
Am 03.11.2023 um 19:18:49 Uhr schrieb Nick Howitt via bind-users: > Can the bind-internal not be made to caching only and not > authoritative? If so, how? Of course it can, simply remove the zone configuration, but it will then cache the records from the authoritative server (your "external-bind

Re: How should I configure internal and external DNS servers

2023-11-03 Thread Marco M.
Am 03.11.2023 um 19:54:32 Uhr schrieb Nick Howitt: > How do you mean remove the zone information? In your /etc/bind are configuration files. Look for named.conf* and find those that include zones: zone "f.8.1.1.0.7.1.0.1.0.a.2.ip6.arpa" { type master; file "/etc/bind/db.f.8.1.1.0.7.1.0.1.0.a.2.i

Re: How should I configure internal and external DNS servers

2023-11-03 Thread Marco M.
Am 03.11.2023 um 20:12:59 Uhr schrieb Nick Howitt via bind-users: > I have those lines, but if I remove them, then presumably I cannot > have internal overrides anywhere, like a hosts file would or like > dnsmasq would? BIND doesn't care about /etc/hosts. If you make it authoritative for a zone,

Re: How should I configure internal and external DNS servers

2023-11-04 Thread Marco M.
Am 04.11.2023 um 19:41:44 Uhr schrieb Nick Howitt via bind-users: > Thanks for the reply. Interesting. > Option A - It works but I would like to stop maintaining two > different servers with the same data. > Option B - I have no chance of getting the company to agree to IPv6. Then you are in a st

what's wrong with the e.hushpuppies-australia.com delegation @ns.domainnetwork.se ?

2012-02-27 Thread M. Meadows
dig -t any e.hushpuppies-australia.com @ns.domainnetwork.se ; <<>> DiG 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 <<>> -t any e.hushpuppies-australia.com @ns.domainnetwork.se ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19181 ;; flags: qr rd; QUERY:

RE: what's wrong with the e.hushpuppies-australia.com delegation @ns.domainnetwork.se ?

2012-02-27 Thread M. Meadows
Mmmm ... nevermind. Nothing wrong with the delegation. The e.hushpuppies-australia.com zone file isn't set up yet! Sorry. From: sun-g...@live.com To: bind-users@lists.isc.org Subject: what's wrong with the e.hushpuppies-australia.com delegation @ns.domainnetwork.se ? Date: Mon, 27 Feb 20

dig -t txt output variation

2012-03-09 Thread M. Meadows
We've noticed that the following command gets a variable result: dig -t txt exacttarget.com @ns2.exacttarget.com +short We get 2 results from this. Seems to be somewhat random. They are: "v=spf1 a mx ip4:207.250.79.101 ip4:207.67.98.192/27 ip4:72.18.216.98 include:cust-spf.exacttarget.com inc

RE: dig -t txt output variation

2012-03-09 Thread M. Meadows
Thanks to both of you for your feedback. I see the rrset ordering explanation in the arm. Good information. > To: sun-g...@live.com > CC: bind-users@lists.isc.org > Subject: Re: dig -t txt output variation > From: wbr...@e1b.org > Date: Fri, 9 Mar 2012 13:54:47 -0500 > > sun-guru wrote on 03

Why does a non-delegated sub-domain work?

2012-05-07 Thread M. Meadows
So ... if we have exacttarget.com delegated to ns1 and ns2.exacttarget.com nameservers and ... we manage the s6.exacttarget.com zone file from ns1 and ns2.exacttarget.com but we don't delegate s6 in the exacttarget.com zone file ... forgot to enter it in the zone file ... how is it

RE: Why does a non-delegated sub-domain work?

2012-05-07 Thread M. Meadows
e file for s6, it follows the NS records of the parent which happen to be the same name server as s6. On the other hand, if you had attempted to master s6 on a different name server, it would not have worked. On 05/07/2012 12:32 PM, M. Meadows wrote: So ... if we have exacttarget.com de

question about how a particular dig works ...

2012-09-18 Thread M. Meadows
dig www.careerone.com.au +short @8.8.8.8 www.careerone.com.au.edgesuite.net. a903.g.akamai.net. 208.44.23.99 208.44.23.121 Why does the above dig work when dig careerone.com.au +nssearch @8.8.8.8 SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server usw1.ak

RE: question about how a particular dig works ...

2012-09-18 Thread M. Meadows
om > > > On 18 Sep 2012, at 14:45, M. Meadows wrote: > > > dig www.careerone.com.au +short @8.8.8.8 > > www.careerone.com.au.edgesuite.net. > > a903.g.akamai.net. > > 208.44.23.99 > > 208.44.23.121 > > > > Why does the above dig work when >

cname and soa record in the same zone file -- problem?

2012-09-18 Thread M. Meadows
Why / how does this work? dig -t any www.careerone.com.au @ns2.tmpw.net. ; <<>> DiG 9.3.6-P1-RedHat-9.3.6-20.P1.el5_8.2 <<>> -t any www.careerone.com.au @ns2.tmpw.net. ;; global options: printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15513 ;; flags: qr aa rd; QUER

RE: question about how a particular dig works ...

2012-09-18 Thread M. Meadows
On 9/18/2012 9:45 AM, M. Meadows wrote: dig www.careerone.com.au +short @8.8.8.8 www.careerone.com.au.edgesuite.net. a903.g.akamai.net. 208.44.23.99 208.44.23.121 Wh

does a stub zone require an IXFR?

2012-09-20 Thread M. Meadows
Attempting to determine if a stub zone requires any kind of zone transfer. Reading through online doc I find mixed opinions. Here's one: … Stub-Zones do receive their information by just querying DNS-Servers instead of requesting a Zone-Transfer. You can even add Stub-Zones for Zones where Z

limitations of dig +nssearch

2012-10-31 Thread M. Meadows
Does anyone know why dig brownmackie.com +nssearch only returns 5 auth nameserver soa records? A check of whois shows they have 7 auth nameservers. A dig -t NS brownmackie.com @ shows 7 nameservers are delegated authority for the domain. Is this a limitation of +nssearch? Can +nssearch only

question about dns query distribution

2013-02-06 Thread M. Meadows
Recently noticed that for 2 nameservers ns1.tbd.com and ns2.tbd.com (names are changed to protect the innocent) the first nameserver consistently receives twice as many queries as the 2nd nameserver. Who can tell me why queries are distributed this way? Any ideas? I assume it's something rel

RE: question about dns query distribution

2013-02-08 Thread M. Meadows
They are authoritative nameservers. Thanks for the reply! Date: Wed, 6 Feb 2013 16:12:51 -0500 From: lkc...@ksu.edu To: bind-users@lists.isc.org Subject: Re: question about dns query distribution Are these authoritative nameservers or resolving DNS servers? If the latter, its probably because

RE: question about dns query distribution

2013-02-08 Thread M. Meadows
at 11:32 AM, M. Meadows wrote: Recently noticed that for 2 nameservers ns1.tbd.com and ns2.tbd.com (names are changed to protect the innocent) the first nameserver consistently receives twice as many queries as the 2nd nameserver. Who can tell me why queries are distributed this way? I

MX failed lookup and BIND

2013-02-15 Thread M. Meadows
We're seeing email failures to outlook.uga.edu. dig uga.edu +nssearch shows only dns3.uga.edu responds with an soa record. and dig -t mx outlook.uga.edu @dns3.uga.edu returns an mx record. outlook.uga.edu.86400 IN MX 10 707341637.mail.outlook.com. And we see a proble

Understanding rndc referral statistics

2013-03-29 Thread M. Meadows
Question about rndc referral data. Running BIND 9.3 on an older nameserver and BIND 9.7 on a somewhat newer one. These 2 nameservers sit under a load balancer and get an equal number of queries. While examing rndc output on the 2 nameservers I noticed that the older one does about 100 referrals

RE: Understanding rndc referral statistics

2013-03-29 Thread M. Meadows
Thinking about this ... perhaps this is more to do with the behavior of BIND 9.3 versus BIND 9.7. Did the referral mechanism change? Here are my thoughts on the subject: Nameserver A is the authority for zone1.com and it is the authority for sub.zone1.com. Sub.zone1.com is delegated from zone1.

rndc stats - referral versus failure

2013-04-09 Thread M. Meadows
Looking at rndc stats output on an older BIND 9.3 nameserver versus output on a new BIND 9.7 nameserver. It seems that the 9.3 and 9.7 referrals and failures are flipped in rndc stats output. Does that make sense? On the 9.3 nameserver I see a boatload of referrals and almost no failures. On

Looking for info about BIND support for International Domain Names

2013-09-24 Thread M. Meadows
Wondering about IDN support for BIND. UTF-8 character set? Searched for these in this forum and didn't find much. May have missed it. Anything helpful already out there for review? Thanks! Martin Meadows Indianapolis, IN _

installation issues

2016-05-08 Thread Rajesh M
hi i tried running the following bind versions on win 2008 r2 server 32 bit and 64 bit 9.9.9 9.10.4 i am getting error this is not a valid win32 application. also i noted that plesk (parallels) uses BIND DNS Server 9.10.3-P4 (for windows) i could not see this version on the website of bind

Re: installation issues

2016-05-08 Thread Rajesh M
[mailto:b...@jubileegroup.co.uk] To: bind-users@lists.isc.org Sent: Sun, 8 May 2016 14:12:49 +0100 (BST) Subject: Re: installation issues Hi there, On Sun, 8 May 2016, Rajesh M wrote: > i am getting error this is not a valid win32 application. I suspect that you've downloaded the wrong archiv

Re: installation issues

2016-05-12 Thread Rajesh M
@lists.isc.org Sent: Mon, 9 May 2016 12:32:42 +0100 Subject: Re: installation issues Rajesh M <24x7ser...@24x7server.net> wrote: > > however after installation i am getting the same error as earlier > > The ISC BIND service failed to start due to the following error: > ISC BIND

Re: installation issues

2016-05-13 Thread Rajesh M
, 13 May 2016 07:39:33 +0200 Subject: Re: installation issues Am 13.05.2016 um 05:20 schrieb Rajesh M: > @ tony finch > your post helped me. thank you very much. > i created a folder called c:\BindDNS and installed in that. > it worked correctly > > is anybody on this list using bind

Binding DNS server to a particular IP address

2008-12-03 Thread Jerry M
I have two different IP addresses coming into my server. I need to guarantee that ISC BIND only monitors and replies to requests coming from one of the two IP addresses. I can't seem to find a configuration parameter that tells the server which IP address to listen on. How do I configure that

how to see ALL NS records in a zone file with dig

2010-11-12 Thread M. Meadows
If I use dig NS I know I will see the NS records for the domain. I know I can do the same thing for other RR types. In the case where a zone file has RR records that define delegation for subdomains why can't I use this dig command to see those delegations? I assume this is easy and it's jus

RE: how to see ALL NS records in a zone file with dig

2010-11-15 Thread M. Meadows
> Subject: RE: how to see ALL NS records in a zone file with dig > > On Mon, 15 Nov 2010, M. Meadows wrote: > > Thanks for the reply Jay. Does that work for you? It doesn't work for me. > > Yep, it works for me. Here's an example for zone healthcare.uiowa.edu with &g

problem getting address record for google public dns server

2010-11-16 Thread M. Meadows
Can someone explain the following dig results? The first dig @8.8.8.8 provides the expected result : dig +noall +answer google-public-dns-a.google.com @8.8.8.8 google-public-dns-a.google.com. 85040 IN A 8.8.8.8 We get the same result from KLOTH.NET (http://www.kloth.net/services/nslook

Summary: problem getting address record for google public dns server

2010-11-22 Thread M. Meadows
0:35 2010 ;; MSG SIZE rcvd: 259 Looking at the flags in the response note the lack of 'ra'; Recursion Available! Thus the server is saying I don't know (or I wont tell you what's in my cache) and I'm not going to find an answer for you, go start looking at the root servers. H

BIND 9.3 problem with semi-colon comments in zone file

2011-01-18 Thread M. Meadows
We've seen DNS reload issues with zone files with lines that begin with a ";" that don't have a " " directly after the semi-colon. Tried a google search to see why this happens. Didn't have much luck. Can someone explain? Thanks very much. Martin Meadows

RE: BIND 9.3 problem with semi-colon comments in zone file

2011-01-19 Thread M. Meadows
.org > Subject: Re: BIND 9.3 problem with semi-colon comments in zone file > Date: Wed, 19 Jan 2011 11:48:33 +1100 > > > In message , "M. Meadows" writes: > > > > We've seen DNS reload issues with zone files with lines that begin with a > > ";&q

odd dig results for fqdn

2011-01-25 Thread M. Meadows
: dig mta.news.getaroomgetadeal.com +noall +answer @4.2.2.1 ; <<>> DiG 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 <<>> mta.news.getaroomgetadeal.com +noall +answer @4.2.2.1 ;; global options: printcmd : dig news.getaroomgetadeal.com +nssearch @4.2.2.1 SOA ns1.exacttarget.com. hostmaster.exacttarget.

RE: odd dig results for fqdn

2011-01-25 Thread M. Meadows
are seeing ... where dig on fqdn fails until we do dig with +nssearch on the domain? > Date: Tue, 25 Jan 2011 17:57:33 + > From: d...@dotat.at > To: sun-g...@live.com > CC: bind-users@lists.isc.org > Subject: Re: odd dig results for fqdn > > On Tue, 25 Jan 2

question about thehartford.com domain

2011-06-15 Thread M. Meadows
Good morning. We sent the following email to the dns managers at thehartford.com this morning: - Hi. We’re experiencing some issues with address record lookups for eftc.thehartford.com. We’ve got a coupl

RE: question about thehartford.com domain

2011-06-15 Thread M. Meadows
thehartford.com domain > > > > On Wed, 15 Jun 2011, M. Meadows wrote: > > > Question : our check of whois indicates that ns1.thehartford.com and > > ns2.thehartford.com are > > the authoritative nameservers for thehartford.com. A dig with a +trace for > > eftc.

RE: question about thehartford.com domain

2011-06-15 Thread M. Meadows
.com > CC: bind-users@lists.isc.org > Subject: Re: question about thehartford.com domain > > > > On Wed, 15 Jun 2011, M. Meadows wrote: > > > Question : our check of whois indicates that ns1.thehartford.com and > > ns2.thehartford.com are > > the authori

RE: question about thehartford.com domain

2011-06-17 Thread M. Meadows
; > > In message <4dfa62ca.7060...@gmail.com>, David Sparro writes: > > On 6/15/2011 7:41 PM, M. Meadows wrote: > > > > > > The DNS admins at thehartford.com seem to feel that this nameserver > > > mismatch is working as expected. > > > > &

problem with spinsix.com?

2011-08-30 Thread M. Meadows
Seeing some flakey feedback from spinsix.com domain today. dig spinsix.com +nssearch ... times out or fails. Is that domain borked? Thanks, Martin Meadows ___ Please visit https://lists.isc.org/mailman/listi

RE: problem with spinsix.com?

2011-08-30 Thread M. Meadows
More specifically : Don't understand why dig spinsix.com +nssearch @8.8.8.8 times out xtinunixadmin01 : host -t any spinsix.com 8.8.8.8 Using domain server: Name: 8.8.8.8 Address: 8.8.8.8#53 Aliases: spinsix.com has SOA record ns63.domaincontrol.com. dns.jomax.net. 2011080600 28800 7200 604

Re: Weird IPv6 issue?

2011-09-11 Thread m...@smtp.fakessh.eu
Le dimanche 11 septembre 2011 20:16, SM a écrit : > At 11:01 11-09-2011, Sten Carlsen wrote: > >If I do: dig d6.s-carlsen.dk (d6 is the host in question, it has > > If the type argument is not supplied, dig will perform a lookup for > an A record. > > dig d6.s-carlsen.dk > > Regards, > -sm

Re: Weird IPv6 issue?

2011-09-11 Thread m...@smtp.fakessh.eu
Le dimanche 11 septembre 2011 23:35, vous avez écrit : > On 11/09/2011 21:00, m...@smtp.fakessh.eu wrote: > > I also think the creation of the reverse zone ipv6 > > > > i dont know how to > > IPv6 reverse zones work in very much the same way as IPv4 reverse zones. >

dig nssearch minor mystery

2011-12-05 Thread M. Meadows
Just wondering why dig with nssearch and "@" produced two different answers when I ran it today. I assume the @8.8.8.8 (in the example below) isn't actually happening ... or it happened in one test and not the other. The results below were exactly as I saw them in the order that they are lis

variable dig results

2012-01-06 Thread M. Meadows
Wondering why we get variable results from the following command:dig eftc.thehartford.com (sometimes we get authority section and additional section feedback ... sometimes we don't) Usually we see the following: ; <<>> DiG 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 <<>> eftc.thehartford.com ;;

RE: variable dig results

2012-01-06 Thread M. Meadows
thanks for the helpful feedback guys! > Date: Fri, 6 Jan 2012 10:14:55 -0600 > From: d...@maplepark.com > To: sun-g...@live.com > CC: bind-users@lists.isc.org > Subject: Re: variable dig results > > On Fri, 6 Jan 2012, M. Meadows wrote: > > > > > >

RE: Trouble configuring forwarders for reverse zones.

2009-04-08 Thread M-lists
Thanks Chris. I had actually tried that, but it turned out Windows wasn't answering reverse queries properly so I didn't notice when I had got it right. Once your post pointed out that was the way to go, I got Wireshark on it and quickly noticed Windows was also at fault. One further thing, I'll

RE: Trouble configuring forwarders for reverse zones.

2009-04-09 Thread M-lists
Men & Mice On Apr 8, 2009, at 8:45 AM, M-lists wrote: > Apologies, I meant 10.1.1.0/28 not /24. The addresses used are > arbitrary, > as I don't like detailing my network topology unnecessarily. > Suffice to say > we've had the */28 subnet dished out and h

RE: negative caching time and TTLs

2009-04-14 Thread Lena M
Hello, Which TTL value is supposed to be used for negative caching time? -We are running BIND 9.X as a caching server. We are seeing that NXDOMAIN replies are being cached using $TTL time of a given zone instead of its SOA min TTL time. -Is $TTL suppose to override SOA's min TTL for t

nsupdate delete question

2009-04-30 Thread James M
Hi- While invoking nsupdate within a program I notice that trying to delete a nonexistant host does not return an error. Same thing seems to happen from the command line which I will show next.. [r...@mandy4 ccadns]# nslookup mandy11.example.com Server: 204.62.134.38 Address:204.62

bind and database support

2009-06-01 Thread Lena M
Hello, we are consdiering using BIND with a database backend. Is anyone using Oracle? What databases are you using and what your experience with it? Thank you very much___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

lookup cnames

2009-08-20 Thread James M
[r...@mandy4 ccadns]# rpm -qa|grep bind bind-utils-9.3.2-7.4.20060mlcs4 bind-9.3.2-7.4.20060mlcs4 I've tried but cannot find an option to return cname records for a given host. I did find dig and host command options that allows entering a cname with the result being the host that owns that cname.

bind-9.18.31 compile errors RHEL 7.9

2024-11-05 Thread N M
What changed between bind-9.18.30 and bind-9.18.31 that would cause it to not compile? We can compile bind-9.18.30 just fine but bind-9.18.31 fails with netmgr/udp errors: netmgr/udp.c:813:8: warning: return type defaults to 'int' [enabled by default] static _Atomic(isc_stdtime_t) last_udpsends

Re: bind-9.18.31 compile errors RHEL 7.9

2024-11-07 Thread N M
installed nor do I believe I can install one for my hardware. > > Mark > >> On 6 Nov 2024, at 02:32, N M wrote: >> >> What changed between bind-9.18.30 and bind-9.18.31 that would cause it to >> not compile? We can compile bind-9.18.30 just fine but bind-9.18.3

Re: Deprecation notice for BIND 9.18: Differentiated Services Code Point (DSCP) support

2023-01-05 Thread Robert M. Stockmann
20 because it's already non-operational. > This is like Mercedes Benz announcing they will only sell the Baby Benz model, which is a Volkswagen EV barebonez with the VW logo replaced with a plastic Mercedes Benz star. -- Robert M. Stockmann - RHCE Network Engineer - UNIX/Linux Speciali

Re: 9.18 horrendous

2024-08-24 Thread Robert M. Stockmann
istaken, I know of other local admin who > moved to unbound because of this, I hope we are not next, but I suspect we > will be. > > vent over. > -- Robert M. Stockmann - RHCE Network Engineer - UNIX/Linux Specialist crashrecovery.org st...@stokkie.net -- Visit https://lists.isc

Re: Dig for link-local

2013-03-22 Thread Carlos M. Martinez
link-locals are not that special, with the exception of the % decorator... other than that, they work exactly like any other address. Bind/Apache/ will listen on link locals and they can be used as route next-hops too. regards, ~Carlos On 3/22/13 1:13 PM, Kevin Darcy wrote: > I'm not sure what

Re: Dig for link-local

2013-03-22 Thread Carlos M. Martinez
Transport has nothing to do with content in DNS. If your client asks for an record it will get the appropriate answer according to the zone's records (a value or an error condition) regardless on whether the query was made over IPv6 or IPv4. That said, you can 'hack' around this expected beha

Re: Suspecious DNS traffic

2013-03-25 Thread Carlos M. Martinez
Are you talking about SOURCE or destination ports ? regards ~CArlos On 3/25/13 1:21 PM, babu dheen wrote: > Hi Matus, > > Still not convinced because if i need to allow >1024 port from our DNS > server to external world(internet).. where is the security? > > I beleive we just need to allow TC

Auto-dnssec maintain and 'continous' resigning

2013-04-01 Thread Carlos M. Martinez
Hello all, I have a few zones signed with DNSSEC and "autodnssec maintain". I have one particular zone that every now and then (I'm working on finding a pattern or trigger) This re-signing process runs for a while, incrementing the serial each time and growing the journal until stopping. I know

Re: Auto-dnssec maintain and 'continous' resigning

2013-04-01 Thread Carlos M. Martinez
Reframing the question in more general terms... Which events trigger a zone re-sign and reload when using "auto-dnssec maintain" ? regards, ~Carlos On 4/1/13 12:04 PM, Carlos M. Martinez wrote: > Hello all, > > I have a few zones signed with DNSSEC and "autodnssec

Re: Auto-dnssec maintain and 'continous' resigning

2013-04-04 Thread Carlos M. Martinez
the other options. Looking forward to your thoughts. ~Carlos On 4/3/13 7:48 PM, Mark Andrews wrote: > > In message <515a92a5.3020...@imperial.ac.uk>, Phil Mayers writes: >> On 04/01/2013 07:36 PM, Carlos M. Martinez wrote: >>> Reframing the question in more general ter

Re: signature expiration

2013-04-15 Thread Carlos M. Martinez
If nothing changes, only the SOA serial will be incremented on resign. The signatures don't 'have' to be renewed every 30 days, you can resign as often as you want / need. regards ~Carlos On 4/11/13 9:14 AM, hugo hugoo wrote: > Hello, > > Can anyone tell me why signatures in dnssec mut be ren

Re: ISC Courses

2013-04-26 Thread Carlos M. Martinez
That's stiff... On 4/26/13 2:47 PM, rohan.he...@cwjamaica.com wrote: > Hello, > > Can anyone say why Bind course offering appears so expensive? Is something > else included in the package that is not specified? > > 2-Day Introduction to DNS & BIND Training > Price: $1,795.00 > > Rohan > __

Re: Views Question

2013-04-30 Thread Carlos M. Martinez
I think views have mostly to do with the source of the queries, thus presenting a different 'view' of zone data depending on who the client is. You could have one view only with master zones and other view with salve zones, but I'm not sure what the purpose would be, unless for example you want to

Re: Mailing list "reply-to" setting

2013-05-08 Thread Carlos M. martinez
And, If I might add, adding a tag to the subject like [bind-users] would be extremely nice. regards ~Carlos On 5/8/13 12:02 PM, Steven Carr wrote: > Any chance someone can correct the settings on this mailing list to > reply to the list by default instead of the user posting the message? > > Th

Re: Mailing list "reply-to" setting

2013-05-08 Thread Carlos M. martinez
Agreed, but, subject tagging is very useful for those who prefer to have things hit your inbox first, before archiving. And there seems to be a lot more agreement on the tagging issue than on the reply to. Out of dozens of MLs I'm subscribed to, this is the only one which does not tag the subject,

Re: Mailing list "reply-to" setting

2013-05-09 Thread Carlos M. martinez
On 5/8/13 10:53 PM, Michael McNally wrote: > On 5/8/13 9:43 AM, Carlos M. martinez wrote: >> Agreed, but, subject tagging is very useful for those who prefer to have >> things hit your inbox first, before archiving. And there seems to be a >> lot more agreement on the taggin

Re: Negative zones; NXDOMAIN responses

2013-05-20 Thread Carlos M. Martinez
You need the soa record. It has to be empty but not THAT empty :-) Sent from my iPad On 20 May 2013, at 04:51, Narcis Garcia wrote: > - Yes, I thought about not using DNS from the same internet provider, > but wanted to know if there is a way to patch only the .local response. > > - This is th

Re: Confused about a basic concept

2013-06-05 Thread Carlos M. Martinez
The 'hidden master' setup is a very good strategy for a number of reasons. I think the original description only derails a bit when using the term 'authoritative': > I'm being told "our authoritative DNS >> servers should not receive any queries", as well as "DNS slaves >> respond to quer

Re: This list's prefix

2013-06-05 Thread Carlos M. Martinez
That's a neat trick, thanks Warren! I also do like prefixes, BTW (as can be seen in the other thread referenced). cheers! ~Carlos On 6/5/13 2:46 PM, Warren Kumari wrote: > > On Jun 5, 2013, at 11:43 AM, Narcis Garcia wrote: > >> It's not the only mailing list where I'm subscribed. >> Could p

Re: Rate-Limit Question

2013-06-14 Thread Carlos M. Martinez
You need to patch your 9.9.2 source code and recompile. Take a look at: http://www.redbarn.org/dns/ratelimits cheers, ~Carlos On 6/14/13 11:27 AM, Manson, John wrote: > We are running Bind 9.9.2 and would like to invoke the rate-limit option > but named says ‘unknown option’. > > Do we need to

Re: Rate-Limit Question

2013-06-14 Thread Carlos M. Martinez
Evan, thanks for the heads up. Do you have a estimated time of release for 9.9.4 and 9.9.10 ? Warm regards, ~Carlos On 6/14/13 1:08 PM, Evan Hunt wrote: > On Fri, Jun 14, 2013 at 03:36:19PM +0100, Phil Mayers wrote: >> It's not built into bind (yet). > > Correct. For the record, it'll be in

Re: Rate-Limit Question

2013-06-14 Thread Carlos M. Martinez
tks !! On 6/14/13 1:21 PM, Evan Hunt wrote: > On Fri, Jun 14, 2013 at 01:10:47PM -0300, Carlos M. Martinez wrote: >> thanks for the heads up. Do you have a estimated time of release for >> 9.9.4 and 9.9.10 ? > Every time I make predictions about dates, events conspire to make &

BIND response time is relatively high

2015-01-26 Thread alaa m zidan
hi , I noticed that at peak hours, BIND response time is relatively high for some servers.non-cached query takes over 700msI set some kernel parameters to tune the network and sockets for redhat 6 and set some global options to tune the BIND by modifying the cache settings, but neither I get th

Re: Deprecating BIND 9.18+ on Windows (or making it community improved and supported)

2021-04-30 Thread Robert M. Stockmann
article "C11 atomic variables and the kernel" By Jonathan Corbet, February 18, 2014 https://lwn.net/Articles/586838/ Best Regards, Robert -- Robert M. Stockmann - RHCE Network Engineer - UNIX/Linux Specialist crashrecovery.org st...@stokkie.net _

Problems with compiling BIND 9.17.10 or above ...

2021-05-26 Thread Zhéxué M. @SysAdmin
Dear Ladies and Gentlemen, I wanted to update my BIND server to the current version 9.10.17 and keep getting stuck in the compile process. First I compiled and installed the tool "NGHTTP/2" under "/user/local/nghttp2/1.43.0/". But the "CONFIGURE" - process constantly brings me the error messag

Re: resolving www.ecb.europa.eu tages ages

2022-06-20 Thread Robert M. Stockmann
.net. . 5812IN NS g.root-servers.net. --//-- ;; Received 891 bytes from 147.67.12.3#53(ns2lux.europa.eu) in 16 ms www.ecb.europa.eu. 300 IN CNAME www-ecb-europa-eu.ax4z.com. ;; Received 86 bytes from 2001:502:4612::91#53(pdns109.ultradns.org) in 4 m

Re: resolving www.ecb.europa.eu tages ages

2022-06-20 Thread Robert M. Stockmann
ns1lux.europa.eu) in 18 ms www.ecb.europa.eu. 300 IN CNAME www-ecb-europa-eu.ax4z.com. ;; Received 86 bytes from 156.154.64.109#53(pdns109.ultradns.com) in 25 ms 0.00user 0.00system 0:00.56elapsed 0%CPU (0avgtext+0avgdata 17072maxresident)k 0inputs+0outputs (15major+1204minor)pagefaults

TTL is varying across nameservers

2022-09-24 Thread Robert M. Stockmann
;; ANSWER SECTION: stokkie.net.21600 IN A 84.87.53.162 ;; Query time: 23 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Sun Sep 25 07:46:18 2022 ;; MSG SIZE rcvd: 45 $ Is this proper behavior ? -- Robert M. Stockmann - RHCE Network Engineer - UNIX/Linux Specialist crash

Reverse lookups failing

2008-11-18 Thread Davenport, Steve M
Hello, I am having issues with reverse lookups failing and can not find the cause. Running bind 9.3.5-P1 and 9.3.6rc1. On an external server dig gives: $ dig @harley.mc.utmck.edu -x 165.6.6.27 ; <<>> DiG 9.5.0-P1 <<>> @harley.mc.utmck.edu -x 165.6.6.27 ; (1 server found) ;; global options: pr

RE: Slave Servers Return SERVFAIL

2008-11-18 Thread Davenport, Steve M
Hello, I am having issues with reverse lookups failing and can not find the cause. Running bind 9.3.5-P1 and 9.3.6rc1. On an external server dig gives: $ dig @harley.mc.utmck.edu -x 165.6.6.27 ; <<>> DiG 9.5.0-P1 <<>> @harley.mc.utmck.edu -x 165.6.6.27 ; (1 server found) ;; global options: pr

RE: Reverse lookups failing

2008-11-18 Thread Davenport, Steve M
Please disregard. This is working now. Was either an ASA firewall dns filter which was stopped and restarted during testing or the setting of both nameservers to run bind9.3.5-P2. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Davenport, Steve M

RE: Reverse lookups failing

2008-11-18 Thread Davenport, Steve M
Davenport, Steve M Sent: Monday, November 17, 2008 8:20 PM To: [EMAIL PROTECTED] Subject: Reverse lookups failing Hello, I am having issues with reverse lookups failing and can not find the cause. Running bind 9.3.5-P1 and 9.3.6rc1. On an external server dig gives: $ dig @harley.mc.utmck.edu -x

RE: Workaround Solaris's kernel bug

2008-11-20 Thread Davenport, Steve M
Is the correct procedure to make this define: STD_CDEFINES='-DISC_SOCKET_USE_POLLWATCH' export STD_CDEFINES ./configure make -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thomas Schulz Sent: Wednesday, November 19, 2008 4:25 PM To: bind-users@lists.i

bind image size

2008-12-01 Thread Davenport, Steve M
I have a server running Solaris10 and bind9.3.6 compiled with gcc3.3.2. The build was done with ./configure, make. The image size seems rather large at 10637668 bytes vs 4459328 bytes on a different Solaris10 system. Any ideas about the image size difference?

RE: bind image size

2008-12-02 Thread Davenport, Steve M
--- Davenport, Steve M [Mon, Dec 01, 2008 at 05:03:06PM -0500]: --- > I have a server running Solaris10 and bind9.3.6 compiled with gcc3.3.2. The build was done with ./configure, make. The image size seems rather large at 10637668 bytes vs 4459328 bytes on a different Solaris10 system. Any ideas about

can't see nameserver externally

2008-12-09 Thread Davenport, Steve M
Hello, I noticed that one of our nameservers is no longer responding with the correct address externally. The server is ns-2.hosp.utmck.edu and is listed as a server in the registration record for utmck.edu. The address should be 165.6.6.27 but a dig/nslookup from an external site returns 165.6.

delegating to 3rd Windows nameserver

2009-01-13 Thread Davenport, Steve M
Hello, We have nameservers supporting utmck.edu and delegate the zones used by Windows to Windows nameservers as follows: $ORIGIN utmck.edu. _tcp IN NS pri1.utmck.edu. IN NS sec1.utmck.edu. _udp IN NS pri1.utmck.edu. IN NS

bind-9.7.2-P3 linux how to debug/troubleshoot query failures?

2011-02-03 Thread Tory M Blue
Hey all, Well I'm reaching out as I'm at a loss. I have a distributed DNS architecture with 2 bind-9.7.2-P3 servers behind an F5 Loadbalancer. I then have another 2 behind another F5 at another location. My app servers are configured with their resolv.conf looking like: (please ignore the domain

  1   2   >