Re: pre heat cache

2016-02-17 Thread bert hubert
On Wed, Feb 17, 2016 at 11:31:54AM -0800, William Taylor wrote: > Is there anyway to pre-heat the cache in bind on startup besides having > a custom script that did a bunch of queries on top hosts? > I know you can dump it with rndc but can you load it back ? One way to achieve this is to have two

Re: BIND 9.11 / edns-client-subnet

2016-05-09 Thread bert hubert
On Mon, May 09, 2016 at 04:38:13PM +0200, Nico CARTRON wrote: > I was wondering whether some folks on the mailing list had a look at the ECS > implementation in BIND 9.11, > and if they had any feedback to share? Perhaps you should tell us how it works for you, what your testing has found, and co

Re: BIND 9.11 / edns-client-subnet

2016-05-09 Thread bert hubert
On Mon, May 09, 2016 at 05:24:50PM +0200, Nico CARTRON wrote: > > Perhaps you should tell us how it works for you, what your testing has  > > found, and contribute to the development of great open source software?  > well, I am just starting the tests now, so cannot tell - yet :) > I will definitel

Re: New type of DDoS? Anyone saw it?

2016-05-16 Thread bert hubert
On Mon, May 16, 2016 at 05:03:01PM +0200, Marek Królikowski wrote: > Today i saw my bind eat almost 90% of RAM when i check logs I find > interesting DDoS on my DNS Cluster today: > 16-May-2016 16:47:47.467 client 8X.1X0.3Y.40#44968: query: 323.016.231.212 > IN + (8X.1X0.Y.Y) This may be rela

Re: New type of DDoS? Anyone saw it?

2016-05-16 Thread bert hubert
On Mon, May 16, 2016 at 09:20:17PM +0200, Marek Królikowski wrote: > Hello > I just call to one of the client who do this DDoS and he confirm, he use UBI > devices > Anyone know how to block all query like this: "query 331.206.372.214 IN > " with random AAA.XXX.YYY.ZZZ address? Marek,

Re: ISC considering a change to the BIND open source license

2016-06-14 Thread bert hubert
On Mon, Jun 13, 2016 at 08:57:02PM +, P Vixie wrote: > This is long overdue. I'm all for it. Vixie For what it is worth, as open source fellow travellers we discussed this earlier both with Vicky and Paul, and we are in strong agreement with this measure to increase the sustainability of great

Re: Load balancer for Bind

2016-09-14 Thread bert hubert
On Wed, Sep 14, 2016 at 06:17:13PM +0200, Job wrote: > which is the best load balancer for two or more Bind DNS Server, located in > the same farm? > I read something about HAProxy but it does not manage udp connection and the > interesting security proxy/balancer DnsDist does not pass original c

Re: Load balancer for Bind

2016-09-15 Thread bert hubert
On Wed, Sep 14, 2016 at 03:41:31PM -0400, Matthew Pounsett wrote: > > I read something about HAProxy but it does not manage udp connection and > > the interesting security proxy/balancer DnsDist does not pass original > > client ip for Bind-DLZ... > > > Your best option is something that can do the

Re: Load balancer for Bind

2016-09-16 Thread bert hubert
On Fri, Sep 16, 2016 at 02:03:31PM +0100, Phil Mayers wrote: > >Sorry for running advertisement here. But please know dnsdist is software > >neutral, it is not "powerdnsdist". > > I've never come across dnsdist before. Would you describe it as > production-ready? Hi Phil, A large CDN, one of .nl

Re: Load balancer for Bind

2016-09-16 Thread bert hubert
On Fri, Sep 16, 2016 at 02:22:24PM +0100, Phil Mayers wrote: > I was mainly wondering about the comment: > > """ > dnsdist is still very fresh software. However, we are actively seeking Hi Phil, Thanks - that statement was accurate in March 2015 when we posted that item. I have now replaced it w

Re: Intermittent NXDOMAIN, Bind 9.2.3 config and PowerDNS problem?

2009-07-30 Thread bert hubert
On Mon, Jul 27, 2009 at 11:36 AM, Richard wrote: > (This problem involves bind, but it's not about bind strictly > speaking.  Is there a general DNS discussion list somewhere?  If so, > please direct me.) dns-operations might come reasonably close. Historically, this list used to be 'the' place, b