Re: Nslookup not working for external domain

2010-11-18 Thread Matus UHLAR - fantomas
On 17.11.10 11:10, Moore, Mark A. wrote: > Subject: Nslookup not working for external domain oh, nslookup is not working? Sure it is working, your problem is not in nslookup. > We are running into a issue where one of our slave servers isn't resolving > non-local domain names. the term "slave" o

Re: High named CPU every 10 minutes?

2010-11-18 Thread Joao Damas
For recursive DNS servers, please run something that is 9.5 or later as there were significant improvements in the cache handing that address what you are describing Joao On 17 Nov 2010, at 20:26, blrmaani wrote: > I see a peculiar behavior on my DNS server. The named CPU reaches 90% > + every

"broken trust chain" for non-existing AAAA records

2010-11-18 Thread lst_hoe02
We are using Bind 9.7 at the border to resolve DNS queries for a small LAN. After moving forward in using IPv6 we discovered many "broken trust chain" errors in the bind log for non existing records. One example is Nov 18 01:18:21 firewall named[27580]: error (broken trust chain) res

RE: Nslookup not working for external domain

2010-11-18 Thread Moore, Mark A.
I have figured out and resolved my issue. For some reason I could not read the contents of the db.rootcache file. So I deleted and downloaded a new copy. Now everything is working. Thx to all for your assistance. Mark From: Moore, Mark A. Sent: Wednesday, November 17, 2010 1:10 PM To: bind-use

Re: Is it Possible to Log nxdomain Responses?

2010-11-18 Thread Anand Buddhdev
On 17/11/2010 15:23, Stephane Bortzmeyer wrote: > On Wed, Nov 17, 2010 at 07:48:55AM -0600, > Martin McCormick wrote > a message of 22 lines which said: > >> It would be nice to log each nxdomain for a while so we can verify >> that the new deligated zone we are about to install fixed the >>

Re: Nslookup not working for external domain

2010-11-18 Thread Kevin Darcy
On 11/18/2010 5:16 AM, Matus UHLAR - fantomas wrote: On 17.11.10 11:10, Moore, Mark A. wrote: Subject: Nslookup not working for external domain oh, nslookup is not working? Sure it is working, your problem is not in nslookup. We are running into a issue where one of our slave servers isn't re

Best Practices Query Logging, On or Off ?

2010-11-18 Thread CT
I am looking for a best practices for dns query logging Versions in use on Linux... - BIND 9.7.1-P2 - BIND 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 The minimum logging statement in my test named.conf (bind 9.7.1-P2) logging { category lame-servers { null; }; category resolver

Re: Nslookup not working for external domain

2010-11-18 Thread Matus UHLAR - fantomas
>> On 17.11.10 11:10, Moore, Mark A. wrote: >>> nslookup www.cnn.com >>> ;; Got SERVFAIL reply from 192.243.160.18, trying next server > On 11/18/2010 5:16 AM, Matus UHLAR - fantomas wrote: >> This server apparently does not provide recursion for you. On 18.11.10 12:44, Kevin Darcy wrote: > The O

Re: Nslookup not working for external domain

2010-11-18 Thread Kevin Darcy
On 11/18/2010 2:18 PM, Matus UHLAR - fantomas wrote: On 17.11.10 11:10, Moore, Mark A. wrote: nslookup www.cnn.com ;; Got SERVFAIL reply from 192.243.160.18, trying next server On 11/18/2010 5:16 AM, Matus UHLAR - fantomas wrote: This server apparently does not provide recursion for you. On 1

Re: Best Practices Query Logging, On or Off ?

2010-11-18 Thread Kevin Darcy
On 11/18/2010 1:36 PM, CT wrote: I am looking for a best practices for dns query logging Versions in use on Linux... - BIND 9.7.1-P2 - BIND 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 The minimum logging statement in my test named.conf (bind 9.7.1-P2) logging { category lame-servers { null;

Re: Best Practices Query Logging, On or Off ?

2010-11-18 Thread Russell Jackson
On 11/18/2010 12:19 PM, Kevin Darcy wrote: On 11/18/2010 1:36 PM, CT wrote: I am looking for a best practices for dns query logging Versions in use on Linux... - BIND 9.7.1-P2 - BIND 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 The minimum logging statement in my test named.conf (bind 9.7.1-P2) loggin

Re: Debugging "configuring TKEY: failure" (w/samba4)

2010-11-18 Thread Adam Tauno Williams
On Fri, 2010-11-12 at 07:54 -0700, Nicholas F Miller wrote: > I recently went through this and have it working. Look through the > archives for 'GSS-TSIG and Active Directory'. > https://lists.isc.org/mailman/mmsearch/bind-users?config=bind-users.htsearch&restrict=&exclude=&method=and&format=short&

Re: Debugging "configuring TKEY: failure" (w/samba4)

2010-11-18 Thread Adam Tauno Williams
On Thu, 2010-11-18 at 16:20 -0500, Adam Tauno Williams wrote: > On Fri, 2010-11-12 at 07:54 -0700, Nicholas F Miller wrote: > > I recently went through this and have it working. Look through the > > archives for 'GSS-TSIG and Active Directory'. > > https://lists.isc.org/mailman/mmsearch/bind-users

Re: Best Practices Query Logging, On or Off ?

2010-11-18 Thread Kevin Darcy
On 11/18/2010 4:10 PM, Russell Jackson wrote: On 11/18/2010 12:19 PM, Kevin Darcy wrote: On 11/18/2010 1:36 PM, CT wrote: I am looking for a best practices for dns query logging Versions in use on Linux... - BIND 9.7.1-P2 - BIND 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 The minimum logging statemen

Re: Best Practices Query Logging, On or Off ?

2010-11-18 Thread CT
Kevin Darcy wrote, On 11/18/2010 02:19 PM: On 11/18/2010 1:36 PM, CT wrote: I am looking for a best practices for dns query logging Versions in use on Linux... - BIND 9.7.1-P2 - BIND 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 The minimum logging statement in my test named.conf (bind 9.7.1-P2) loggin

Re: "broken trust chain" for non-existing AAAA records

2010-11-18 Thread Mark Andrews
In message <20101118131400.37717e5p5tard...@webmail.kwsoft.de>, lst_ho...@kwsof t.de writes: > We are using Bind 9.7 at the border to resolve DNS queries for a small > LAN. After moving forward in using IPv6 we discovered many "broken > trust chain" errors in the bind log for non existing

Re: Nslookup not working for external domain

2010-11-18 Thread Barry Margolin
In article , "Moore, Mark A." wrote: > I have figured out and resolved my issue. For some reason I could not read > the contents of the db.rootcache file. So I deleted and downloaded a new > copy. Now everything is working. Thx to all for your assistance. I thought BIND now has a compiled-in

Re: Nslookup not working for external domain

2010-11-18 Thread Mark Andrews
In message , Barry Margolin writes: > In article , > "Moore, Mark A." wrote: > > > I have figured out and resolved my issue. For some reason I could not read > > > the contents of the db.rootcache file. So I deleted and downloaded a new > > copy. Now everything is working. Thx to all for yo

Re: Nslookup not working for external domain

2010-11-18 Thread Matus UHLAR - fantomas
> > In article , > > "Moore, Mark A." wrote: > > > > > I have figured out and resolved my issue. For some reason I could not > > > read > > > > > the contents of the db.rootcache file. So I deleted and downloaded a new > > > copy. Now everything is working. Thx to all for your assistance.