[Unbound-users] Improve avg response times

2012-07-06 Thread vinay3
I am using an amazon large EC2 instance (4ECUs, 2 cores) for my unbound configured as below. I am seeing a 150ms+ average response time as reported by namebench Alexa 2K result. In order to reduce my lookup times, I am running an hourly scan of these 35K sites (from namebench dat files) in order to

Re: [Unbound-users] Servers for local zones that are not signed

2012-07-06 Thread Eugene Crosser
On 07/06/2012 04:45 PM, W.C.A. Wijngaards wrote: So unbound asks dnsmasq for the address of "myhost.lan" as it is instructed by forward-zone, gets correct result (!), but then marks it bogus because it cannot establish trust chain. >>> >>> You'll need >>> >>> private-domain: "lan."

Re: [Unbound-users] Servers for local zones that are not signed

2012-07-06 Thread W.C.A. Wijngaards
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Eugene, On 07/06/2012 02:25 PM, Eugene Crosser wrote: > On 07/06/2012 03:33 PM, Jan-Piet Mens wrote: >>> So unbound asks dnsmasq for the address of "myhost.lan" as it >>> is instructed by forward-zone, gets correct result (!), but >>> then marks it

Re: [Unbound-users] Servers for local zones that are not signed

2012-07-06 Thread Eugene Crosser
On 07/06/2012 03:33 PM, Jan-Piet Mens wrote: >> So unbound asks dnsmasq for the address >> of "myhost.lan" as it is instructed by forward-zone, gets correct result (!), >> but then marks it bogus because it cannot establish trust chain. > > You'll need > > private-domain: "lan." >

Re: [Unbound-users] Servers for local zones that are not signed

2012-07-06 Thread Jan-Piet Mens
> So unbound asks dnsmasq for the address > of "myhost.lan" as it is instructed by forward-zone, gets correct result (!), > but then marks it bogus because it cannot establish trust chain. You'll need private-domain: "lan." domain-insecure: "lan." Regards, -JP __

[Unbound-users] Servers for local zones that are not signed

2012-07-06 Thread Eugene Crosser
Hello all, sorry if this was discussed already, I could not find the answer. I am trying to configure unbound (1.4.5, running on openwrt) to resolve local zones ("lan." and "168.192.in-addr.arpa.") from another DNS server that has them (in my case, dnsmasq: I want DHCP names resolved in the .lan