Re: 50 million records under one domain using Bind

2008-12-13 Thread Matus UHLAR - fantomas
that comes with it for this experiment. what kind of records do you want to store? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: 50 million records under one domain using Bind

2008-12-13 Thread Matus UHLAR - fantomas
the Bind that comes with it for this experiment. 2008/12/13 Matus UHLAR - fantomas uh...@fantomas.sk: what kind of records do you want to store? On 13.12.08 19:01, Vinay Y S wrote: Mostly A, CNAME, MX and TXT records. so they're generic DNS data, nothing special like RBL ? -- Matus UHLAR

Re: 50 million records under one domain using Bind

2008-12-14 Thread Matus UHLAR - fantomas
and values have significant effect on the result of this experiment? for example, rbldnsd supports only a few types of records, but can store them very effectively, e.g. IP addresses. For all types of DNS records and values, it's apparently not useful -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: is this a valid zone file?

2008-12-21 Thread Matus UHLAR - fantomas
no NS server defined for the zone, just the ranges of the zone. Is that valid? it is, but may cause problems. NS records for the zone itself should be defined. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: is this a valid zone file?

2008-12-22 Thread Matus UHLAR - fantomas
) or cache. That has no NS server defined for the zone, just the ranges of the zone. Is that valid? it is, but may cause problems. NS records for the zone itself should be defined. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: cache poisoning counter-measures

2009-01-05 Thread Matus UHLAR - fantomas
be allowed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user friendly, it's just selective who its friends

Re: Issues in delegating to subdomain owned by other company

2009-01-10 Thread Matus UHLAR - fantomas
for failure? yes -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfamiliar territory

Re: Disable cache in bind 9.6

2009-01-20 Thread Matus UHLAR - fantomas
On 20.01.09 12:49, Dmitry Rybin wrote: How to disable cache in bind-9.6? ttl=0 - bad idea. Matus UHLAR - fantomas wrote: if you know that setting TTL to 0 is a bad idea, why do yuo think that disabling a cache in BIND is not a bad idea? On 20.01.09 18:39, Dmitry Rybin wrote: Because

Re: denied NS/IN

2009-01-21 Thread Matus UHLAR - fantomas
anything from the bogon networks as // detailed in the bogon ACL. bogon; }; Note that isprime is suggesting an ACL on your firewall or router. Especially when in the article above they ask for NOT blackholing them :) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: Disable cache in bind 9.6

2009-01-21 Thread Matus UHLAR - fantomas
On 20.01.09 12:49, Dmitry Rybin wrote: How to disable cache in bind-9.6? ttl=0 - bad idea. Matus UHLAR - fantomas wrote: if you know that setting TTL to 0 is a bad idea, why do yuo think that disabling a cache in BIND is not a bad idea? Dmitry Rybin wrote: Because under high load

Re: Disable cache in bind 9.6

2009-01-22 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas wrote: This is _NOT_ a problem of BIND. This is a problem of its admin who can't read the docs and set up max-cache-size, which does exactly what is needed in this case. On 21.01.09 17:38, Dmitry Rybin wrote: Hmm... And why bind allocate all system memory, if max

EDNS timeouts - log IP address

2009-01-23 Thread Matus UHLAR - fantomas
Hello, I see that logs of EDNS problems show the RR which was successfully resolved after changind packet size or disabling EDNS, but shouldn't they lot the IP which has this problem? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: reverse lookup to CNAME

2009-01-24 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Emacs is a complicated operating system without good text editor

Re: reverse lookup to CNAME

2009-01-25 Thread Matus UHLAR - fantomas
On Sat, Jan 24, 2009 at 9:21 PM, Matus UHLAR - fantomas uh...@fantomas.sk wrote: if metis.local is a CNAME, the PTR shouldn't point to it. On 25.01.09 10:14, John Bond wrote: could you please explain this. Although it's good to remove irelevant part of the text you are replying

Re: BIND 9.6 Flaw - CNAME vs. A Record in MX Records are NOT Illegal

2009-01-26 Thread Matus UHLAR - fantomas
section processing does not include CNAME records... Thus, if an alias is used as the value of an NS or MX record, no address will be returned with the NS or MX value. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: delegation over authority?

2009-01-27 Thread Matus UHLAR - fantomas
to strange results. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #98652: Operation completed successfully

Re: BIND 9.6 Flaw - CNAME vs. A Record in MX Records are NOT Illegal

2009-01-27 Thread Matus UHLAR - fantomas
, the IP is not returned in the MX query. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. It's now safe to throw off your computer

Re: BIND 9.6 Flaw - CNAME vs. A Record in MX Records are NOT Illegal

2009-01-27 Thread Matus UHLAR - fantomas
mx1.xyz.com which is a CNAME. 2) Get Target Host Address: The A query for mx1.xyz.com delivers the address (A) record of srv1.xyz.com, 1.2.3.4, and also delivers the alias (CNAME) record of mx1.xyz.com. In article glnemv$10n...@sf1.isc.org, Matus UHLAR - fantomas uh

Re: [SPAM] Re: Split view multiple zones

2009-01-28 Thread Matus UHLAR - fantomas
memory, but each view its own memory. Can anyone confirm, and if I'm right, tell me that it will be better in next BIND releases? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: BIND 9.6 Flaw - CNAME vs. A Record in MX Records are NOT Illegal

2009-01-28 Thread Matus UHLAR - fantomas
implementations do return both the A and CNAME. It depends on the query sent. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fighting for peace

Re: disableing EDNS messages bind-9.5.0

2009-01-28 Thread Matus UHLAR - fantomas
: add category edns-disabled { null; }; after verifying your nameserver(s) have an EDNS0 clear path by trying the 2 tests mentioned below by Mark Andrews. I strongly recommend you upgrading the BIND first. Later versions issue that message much less often. -- Matus UHLAR - fantomas, uh

Re: Disable cache in bind 9.6

2009-01-29 Thread Matus UHLAR - fantomas
to clients with ttl 0 :( Yes, that is what Setting TTL to 0 means. ~50 views, can't you really lower the views count? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: BIND 9.6 Flaw - CNAME vs. A Record in MX Records are NOT Illegal

2009-02-01 Thread Matus UHLAR - fantomas
is shining and exposed to the light of day. Once upon a time the world was 'flat'. For some of you, apparently is still is 'flat'. Don Quijote -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie

Re: Caching-only Name server does Zone Updates

2009-02-02 Thread Matus UHLAR - fantomas
only if the zone is configured on the nameserver. Do you have any zones configured (other than .)? How do you know that it's performing zone updates? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: NS validation?

2009-02-09 Thread Matus UHLAR - fantomas
WHOIS record. Is does now. Some registrars require nameservers to have WHOIS records if you want to use them for registering domains. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: referral doubt

2009-02-19 Thread Matus UHLAR - fantomas
.testing.server.comhttp://ns1.testing.server.com/A 192.123.123.23 doesn't responds? will it try to get the others? yes, if it's able to find out their IPs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: query an external nameserver doubt

2009-02-19 Thread Matus UHLAR - fantomas
CNAME ts.example.test2.com If they have recursion or query-cache enabled, they may also respond with ts.example.test2.com A in answer section and example.test.com NS info in authority/additional sections -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: BIND logging

2009-03-05 Thread Matus UHLAR - fantomas
-severity yes; }; category default { nextra_syslog; default_debug; }; -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: dig error

2009-03-10 Thread Matus UHLAR - fantomas
it for an email (especially to a list like this) I see no reason to chide someone for doing it. What about irony? Hello is shorter, simpler and more common on the net, expecially in mailing lists... and he -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: zone transfer from slave to master not working

2009-03-20 Thread Matus UHLAR - fantomas
you are transferring from. Check allow-transfer directive, globally for the nameserver and locally for the configured zone. I think the default is none (check the docs for sure) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Server names for query

2009-03-24 Thread Matus UHLAR - fantomas
how does BIND send notifies? does it send them to _any_ of those IP addresses? Some RFCs in the past iirc assumed that one name with multiple IPs is one multihomed host, which could lead to assumption that it's enough to query one of those IP's. I believe it's not true. -- Matus UHLAR - fantomas

Re: PTR for localhost

2009-03-26 Thread Matus UHLAR - fantomas
, the builtin default zone name is 127.in-addr.arpa and I prefer creating this one. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user

Re: negative caching time and TTLs

2009-04-20 Thread Matus UHLAR - fantomas
to) is clear enough. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #9: Out of error messages

Re: Specific DNS configuration

2009-04-21 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. You have the right to remain silent. Anything you say will be misquoted, then used against you

Re: publish bind9 server

2009-06-05 Thread Matus UHLAR - fantomas
, which means, that a midomain.com maintainer must put there NS records for test.midomain.com pointing to your server. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: SPF/TXT records

2009-06-19 Thread Matus UHLAR - fantomas
mail to hotmail, I think there are better ways to get your mail anywhere. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is like

Re: control channel logging

2009-06-22 Thread Matus UHLAR - fantomas
this fall under? If in doubts and docs won't tell you, just enable print-category yes; -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Chernobyl

Re: NS rr configuration: 1*NS + 4xA vs. 4xNS ?

2009-06-29 Thread Matus UHLAR - fantomas
On 30.06.09 01:08, Mark Andrews wrote: In message 20090629101834.ga31...@fantomas.sk, Matus UHLAR - fantomas writes: I am planning to change NS records in our and our customers' zones. I'll have four nameservers on different networks, and I'd like to make configuration as easy

Re: NS rr configuration: 1*NS + 4xA vs. 4xNS ?

2009-06-29 Thread Matus UHLAR - fantomas
In message 20090629200938.ga6...@fantomas.sk, Matus UHLAR - fantomas writes: On 30.06.09 01:08, Mark Andrews wrote: In message 20090629101834.ga31...@fantomas.sk, Matus UHLAR - fantomas wri tes: I am planning to change NS records in our and our customers' zones. I'll have

Re: host -t txt _domainkey.fakessh.eu. bitsy.mit.edu.

2009-07-01 Thread Matus UHLAR - fantomas
On 01.07.09 16:53, fake...@fakessh.eu wrote: it would be possible to add this server bitsy.mit.edu. in / etc / resolv.conf to increase the speed of propagation - /etc/resolv.conf can only contain IPs. - /etc/resolv.conf is not a BIND issue. - propagation of what? -- Matus UHLAR - fantomas

Re: rDNS Round-Robin

2009-07-22 Thread Matus UHLAR - fantomas
. With most of applications doing reverse resolution and using its result anyhow it's still better to have always the same name... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: SRV Record Priority set by IP Address

2009-07-29 Thread Matus UHLAR - fantomas
, some time ago I've been having similar problems, it seemed that nss_lwres was responsible for that. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: [SPAM] Win2k and bind

2009-07-30 Thread Matus UHLAR - fantomas
so), new BIND won't be compatible with w2k. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. We are but packets in the Internet of life

Re: Disable automatic empty IPv6 zones (with -4 already specified)

2009-07-30 Thread Matus UHLAR - fantomas
On 30.07.09 10:35, Matthew Huff wrote: Is there any way to disable BIND from loading the automatic empty zones (D.F.IP6.APRA, etc...). They are being generated even with the -4 command line. have you looked at the disable-empty-zone configuration directive? -- Matus UHLAR - fantomas, uh

Re: idsable ipv6 in config?

2009-07-30 Thread Matus UHLAR - fantomas
. default is over used. oh, although it should work, it's a bit dirty workaround... it needs a statefull firewall allowing only replies to go out... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: idsable ipv6 in config?

2009-07-30 Thread Matus UHLAR - fantomas
; }; work? no, it would prevent server from replying v6 requests -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is soft to do

Re: change NXDOMAIN to a A type response

2009-08-03 Thread Matus UHLAR - fantomas
consider that a bad idea. the DNS is used by many applications in many manners and providing false answers can break them in many ways. You won't get different answer on this list, i guess. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Problem with caching domain

2009-08-07 Thread Matus UHLAR - fantomas
? if those records are meant to be used in NS records, yes, they must be changed. This happen with your bind server? this happens with dns servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: problems in forwarding

2009-08-07 Thread Matus UHLAR - fantomas
to try another server. Is that possible? you can configure zone test.es to be forwarded to different server. There is no functionality in BIND that would continue searching for a name when a server responds the name does not exist. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: cache poisoning

2009-08-11 Thread Matus UHLAR - fantomas
On 11.08.09 13:27, Nelson Serafica wrote: I need to set bind to listen to all address. I'm using AMAZON EC2 no, you don't. you configure listening IPs/ports by using listen-on and listen-on-v6. query-source only configures from which IP/port will your requests come from. -- Matus UHLAR

Re: forwarders question

2009-08-12 Thread Matus UHLAR - fantomas
-recursive queries to a forwarding server. I think it would be interesting to know if this behaviour could bring us some benefits but apparently nobody's going to code this... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Logwatch Unmatched Entries

2009-08-17 Thread Matus UHLAR - fantomas
but microsoft had a genial idea so they ask by themselves. it can be turned off but the default is on... sorry, I don't know about the rest... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: Classless CIDR delegation...

2009-08-17 Thread Matus UHLAR - fantomas
. 96.55.139.64.in-addr.arpa. CNAME 96.whatever.55.139.64.in-addr.arpa. or even to: 96.55.139.64.in-addr.arpa. CNAME 96.hicks-net.net. the second way (96/28) is preferred by RFC2317. Ask your ISP which way he requires/supports. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I

Re: hardware requirements per hits

2009-08-17 Thread Matus UHLAR - fantomas
question is what hardware you need to be able to process your traffic. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Support bacteria

Re: hardware requirements per hits

2009-08-19 Thread Matus UHLAR - fantomas
or local socket and parsing that line in the another process. Logging to file is just faster and more reliable unless you use remote logging features of syslog. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: query reply servfail

2009-09-03 Thread Matus UHLAR - fantomas
) to three servers and they all only reply with A record, no NS. I encountered the same problem with different domain under the same circumstances. I think that if www.hsbc.com.hk. is delegated to some servers, they should provide NS and SOA too... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: OpenDNS.com howto

2009-09-03 Thread Matus UHLAR - fantomas
-cache and entries with bind you can flush names and reload config files (to change zones list), which is a bit far from manipulate. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: I have a question concerning the spf

2009-09-03 Thread Matus UHLAR - fantomas
community mailing lists. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up essential liberty to obtain a little temporary

Re: root and in-addr.arpa zone transfers

2009-09-09 Thread Matus UHLAR - fantomas
it and above is list of servers that do allow transfers... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Due to unexpected conditions

Re: slave server

2009-09-11 Thread Matus UHLAR - fantomas
will return domain domain is not exist ? what do you mean query answer? You server will send what it has in the cache or what will serverA return, or an error if serverA is not accessible. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: root and in-addr.arpa zone transfers

2009-09-12 Thread Matus UHLAR - fantomas
On Freitag 11 September 2009 Matus UHLAR - fantomas wrote: - it's quite useless to cache the .arpa and .in-addr.arpa since unlike other TLD's they are hierarchically organised so there won't be any valuable benefit from slaving them, only risks (see above). On 12.09.09 09:27, Michael

Re: Need help on delegation to subdomain/external servers

2009-09-17 Thread Matus UHLAR - fantomas
above). As said, my issue is not really load balancing, but active-standby switching, where only one server will ever respond at any given time. There are packages that do that, using DNS for that is not good idea. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I

Re: Class B Rev Zone?

2009-09-17 Thread Matus UHLAR - fantomas
the server? And, did you query THIS server? What do logs say? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE = Mad Cow Desease ... BSA

Re: Class B Rev Zone?

2009-09-17 Thread Matus UHLAR - fantomas
? And, did you query THIS server? What do logs say? On 17.09.09 16:12, stefan novak wrote: The logs says nothing. So as there is no update of the zone. Just waited a minute or so. did file timestamp change after the change? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

slave zone header in bind8

2009-09-21 Thread Matus UHLAR - fantomas
Hello, IIRC, slave zones transferred to BIND8 had header that informed us when was the zone transferred and from where. Do I remember correctly? If so, when was this feature removed and why? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: DNS server works but keep getting host unreachable resolving error

2009-09-22 Thread Matus UHLAR - fantomas
. The tcpdump would help us, unless you are satisfied with using linux iptables... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 10 GOTO 10

Re: rndc command for erased zone?

2009-09-23 Thread Matus UHLAR - fantomas
reconfig should forget removed zones too, but you may be - either seeing the same zone in other view - see records fetched from other servers after zone was removed -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Query Refused problem

2009-10-01 Thread Matus UHLAR - fantomas
any other allows's ? the first error message indicated that you didn't allow query-cache or recursion for some clients. Apparently you cloned a view but forget to allow either one in the new view... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: socket is not connected error on bind 9.5.1-P3

2009-10-01 Thread Matus UHLAR - fantomas
many of them? Do you allow transfers to all clients? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux - It's now safe to turn on your

Re: Query Refused problem

2009-10-01 Thread Matus UHLAR - fantomas
things as YOU want them to be :-). Could you post your config (and optional includes) somewhere? I still thinkthe real problem lied elsewhere... Matus UHLAR - fantomas schrieb: On 30.09.09 15:59, Sven Eschenberg wrote: When I had no allow-query statement at all in my config, everything

Re: Glue record miunderstanding

2009-10-02 Thread Matus UHLAR - fantomas
. 172800 IN A 208.77.188.44 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 10 GOTO 10 : REM (C) Bill Gates 1998, All Rights

Re: recursion on auth-only server

2009-10-06 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas wrote: I have moved authoritative server to new IP address. I have changed the DNS name pointing to it so the NS would point to the new IP. Now I looked at the traffic and it seems that there are ~4 of 1000 recursive requests sent to it. Are there any known

Re: Query Refused problem

2009-10-06 Thread Matus UHLAR - fantomas
using allow-query help anything, since it defaults to any;. I thought there's something misconfigured on your server... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: SIBLING GLUE address records (A or AAAA)

2009-10-06 Thread Matus UHLAR - fantomas
and only when they are used for .xx zone. And imho, domains should not be registered on servers that do not have their glue records in the proper zone, .xx or other. That would spare servers from many useless lookups. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: slave transfer troubleshooting issue

2009-10-06 Thread Matus UHLAR - fantomas
not seem to attempt a transfer of the additional zones from the master? It seems you did not configure bind to have any slave zones. do you have any slave zone statements on the second server? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Our DNS is vulnerable --need help

2009-10-08 Thread Matus UHLAR - fantomas
recursion only for the ISP's customers, which means, IP ranges assigned to the ISP. configure allow-recursion with your IP ranges. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: adding new RR?

2009-10-15 Thread Matus UHLAR - fantomas
don't think this way is effective,so i'm very appreciate some one could give me a guid, or some example:souce code is perfect Better try to explain what do you want to achieve -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Problems with include in acl file

2009-10-19 Thread Matus UHLAR - fantomas
of multiple files if only plain IP/CIRD list could be loaded within an ACL statement... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: dump cache's content

2009-10-26 Thread Matus UHLAR - fantomas
On 26.10.09 08:08, net...@royal.net wrote: Can I change bind cache's content? you can remove objects via rnds flushname name. You can't forge cache content without modifying BIND source or playing with process' memory. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: New BIND server

2009-10-28 Thread Matus UHLAR - fantomas
that might be unsecure. Only take care about allow-recursion setting if you plan to use it as recursive (if not, recursion no should be in the config)) and that should be enough for now. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Slave to Win2003 DNS

2009-11-01 Thread Matus UHLAR - fantomas
is updated, server again responses to queries etc. I suspect this is not a problem in the BIND, but in the Windows 2003 DNS, but any ideas anyway, what to look in the server? Haven't been playing with the Windows DNS a lot... Is the master updating SOA serial? -- Matus UHLAR - fantomas, uh

Re: Feature request - disable internal recursion cache

2009-11-01 Thread Matus UHLAR - fantomas
those responses? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The early bird may get the worm, but the second mouse gets the cheese

Re: Reverse DNS Dig returning PTR results only with trace option

2009-11-11 Thread Matus UHLAR - fantomas
CNAME delegations. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is like a steel trap - rusty and illegal in 37 states

Re: Bind sometimes SERVFAIL

2009-11-11 Thread Matus UHLAR - fantomas
.in-addr.arpa not found: 3(NXDOMAIN) Use 'dig -x 209.85.255.187 @ns1.isp' and look at NS records and TTLs. Invalid delegations and inconsistent NS records (domain is delegated from parent to different servers than those listed in the domain) often cause these kinds of problems. -- Matus UHLAR

Re: which information is cached?

2009-12-07 Thread Matus UHLAR - fantomas
(or at least all servers have to provide correct informations) otherwise you may find strange problems. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: questions on bind cache with views

2009-12-17 Thread Matus UHLAR - fantomas
-recursion setting is used. The default is { localhost; localnets; }; which is apparently not enough for you. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Remove/add [A] records based upon server availability

2009-12-27 Thread Matus UHLAR - fantomas
level, L3 switches and load balancers exist to have this functionality. Or, it could be checked at application level -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: change ONLY one record in zone

2010-01-14 Thread Matus UHLAR - fantomas
I need to change only one record in zone (not deligated to my server, can't transfer it too) RECORD.DOMAIN.NET IN A 192.168.1.1 to RECORD.DOMAIN.NET IN CNAME RECORD.DOMAIN.ORG Only one record! Is this possible via bind? Matus UHLAR - fantomas wrote: Not if ht domain is not yours. You

Re: Server overwhelmed by rejections?

2010-01-20 Thread Matus UHLAR - fantomas
to your port 53. If you have recursive-only nameserver, you can safely disable requests to it from unauthorized sources and allow only authorized networks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

master server selection / notify

2010-01-20 Thread Matus UHLAR - fantomas
servers, is the one preferred or is the source of NOTIFY ignored and the selection works as usual? I have small farm of servers and when any of them fetches zone from the master and sends notify, I't like others to fetch zone from this one as a small optimization. Thank you. -- Matus UHLAR

Re: Disabling recursion causes browser hangs on clients with auto proxy config

2010-01-25 Thread Matus UHLAR - fantomas
resolved from given hostname. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE = Mad Cow Desease ... BSA = Mad Software Producents Desease

Re: how do I get a slave to send NOTIFY messages?

2010-01-31 Thread Matus UHLAR - fantomas
servers. notify explicit; is here for this usage -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Saving Private Ryan... Private Ryan exists

Re: Deny MX queries for dynamic IP pools

2010-02-01 Thread Matus UHLAR - fantomas
and helping http clients to find out correct site in case of mistake. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. A day without sunshine

Re: Host/nslookup/dig queries wrong server

2010-02-03 Thread Matus UHLAR - fantomas
: 127.0.0.1#53 Aliases: [...] there are two host commands, one comes from bind, one from dunnowhere. check which one do you have installed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: reverse Zone example!

2010-02-06 Thread Matus UHLAR - fantomas
) or customers DNSs! The same applies for reverse and forward zones. There's no difference here. If you can properly configure forward zone, do the same for reverse. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Strange issue - please enlighten me

2010-02-20 Thread Matus UHLAR - fantomas
zone delegation. No, NS delegations ni parent zones are NOT enough. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam = (S)tupid (P

Re: Query denied errors on PTR records for delegated zone

2010-02-23 Thread Matus UHLAR - fantomas
you think the above. bind 9.4 and later has new option allow-query-cache that allows tune this behaviour too and the default is same as allow-recursion. (actually they cross-inherit each other, if either is not set) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: Query denied errors on PTR records for delegated zone

2010-02-23 Thread Matus UHLAR - fantomas
.wemadeusa.com.0-59.173.150.66.in-addr.arpa. Try fixing this first, maybe this is your real problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Differences between 9.3 and later versions

2010-02-23 Thread Matus UHLAR - fantomas
{ all; }; - if you didn't have recursion enabled, you may need to do so now. Note that enabling recursion to anyone is security risk. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Differences between 9.3 and later versions

2010-02-24 Thread Matus UHLAR - fantomas
On Feb 23 2010, Matus UHLAR - fantomas wrote: since 9.5, the default for allow-recursion is { localhost; localnets; }; previous versions used iirc { all; }; On 23.02.10 16:48, Chris Thompson wrote: Actually, that change was made in 9.4. (Some of the cross-inheritance of the different query

  1   2   3   4   5   6   7   8   9   10   >