Re: Testing...

2017-08-30 Thread Adamiec, Lawrence
I see your email on the list.



Thank you.
Larry

__
Lawrence Adamiec
Web Developer/UNIX Admin
Information Technology Services (ITS)
Chicago-Kent College of Law
Illinois Institute of Technology
565 W. Adams St.
Chicago, IL
60661

On Wed, Aug 30, 2017 at 10:20 AM, Alan Clegg  wrote:

> I don't think I can post to this list for some reason.
>
> I'd like to be able to respond to questions, but my responses never seem
> to show up...
>
> this is just a test to see if I am visible on the list.
>
> Thanks!
> AlanC
>
>
> ___
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to
> unsubscribe from this list
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: no servers found

2014-08-21 Thread Adamiec, Lawrence
Jeremy,

I did have "nameserver"and the IP in the resolv.conf file.  I just found
the trouble.  I entered the wrong IP in the resolv.conf for my name
servers.  Now that I have corrected the IPs, everything seems to work OK.

Thanks to everyone who replied.



Thank you.
Larry



On Thu, Aug 21, 2014 at 11:48 AM, Jeremy C. Reed  wrote:

> On Thu, 21 Aug 2014, Adamiec, Lawrence wrote:
>
> > Using dig @My-NAME-SERVER works.  I am not running named on the virtual
> > server using dig @ 127.0.0.1 does not work.
>
> Okay. Then change your /etc/resolv.conf to contain just the "nameserver
> " and IP of that name server (and a couple others if you want) that
> works.
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: no servers found

2014-08-21 Thread Adamiec, Lawrence
Hi,

Using dig @My-NAME-SERVER works.  I am not running named on the virtual
server using dig @ 127.0.0.1 does not work.


Thank you.
Larry



On Thu, Aug 21, 2014 at 11:10 AM, Jeremy C. Reed  wrote:

> In the virtual server, use dig @a.b.c.d with the IP address of the DNS
> servers you want to use to see if that works.
>
> If you are running named in that same virtual server, try dig
> @127.0.0.1.  If that works, then just change your resolv.conf to point
> to only that nameserver 127.0.0.1
>
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: no servers found

2014-08-21 Thread Adamiec, Lawrence
I had someone at our main campus ensure port 53 is open for this zone.  The
zone does have its own IP.  Even with opening the ports, I still get time
out errors.

Does anyone have any other ideas?

Thank you.
Larry



On Tue, Aug 19, 2014 at 4:07 PM, Adamiec, Lawrence  wrote:

> I should have said it was a Solaris 10 zone (container).  I am not using
> VirtualBox, VMware, or other third party software.
>
> Larry
>
>
>
> On Tue, Aug 19, 2014 at 3:54 PM, Charles Swiger  wrote:
>
>> Hi--
>>
>> On Aug 19, 2014, at 1:47 PM, "Adamiec, Lawrence" <
>> ladam...@kentlaw.iit.edu> wrote:
>>
>> I am running BIND 9.6-ESV-R5-P1 on a Solaris 10 server.  I can run
>> queries without specifying a name server on my Solaris servers
>> successfully.  When I try to run a query on a Solaris 10 virtual server, I
>> get "connection timed out; no servers could be reached" error.
>>
>> If I add the name servers from our main campus (or 8.8.8.8) to the
>> virtual server's resolv.conf file, then dig will use the other name server
>> and skip my name server to resolve the query which is successful.
>>
>>
>> It's fairly normal for virtualization stuff to forbid network access from
>> a VM to the host, via some combination of network interface configuration
>> and NAT/firewall rules.
>>
>> If you're using VirtualBox, look into "bridged adaptor", ie:
>>
>>   https://www.virtualbox.org/manual/ch06.html#network_bridged
>>
>> Regards,
>> --
>> -Chuck
>>
>>
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: no servers found

2014-08-19 Thread Adamiec, Lawrence
I should have said it was a Solaris 10 zone (container).  I am not using
VirtualBox, VMware, or other third party software.

Larry



On Tue, Aug 19, 2014 at 3:54 PM, Charles Swiger  wrote:

> Hi--
>
> On Aug 19, 2014, at 1:47 PM, "Adamiec, Lawrence" 
> wrote:
>
> I am running BIND 9.6-ESV-R5-P1 on a Solaris 10 server.  I can run queries
> without specifying a name server on my Solaris servers successfully.  When
> I try to run a query on a Solaris 10 virtual server, I get "connection
> timed out; no servers could be reached" error.
>
> If I add the name servers from our main campus (or 8.8.8.8) to the virtual
> server's resolv.conf file, then dig will use the other name server and skip
> my name server to resolve the query which is successful.
>
>
> It's fairly normal for virtualization stuff to forbid network access from
> a VM to the host, via some combination of network interface configuration
> and NAT/firewall rules.
>
> If you're using VirtualBox, look into "bridged adaptor", ie:
>
>   https://www.virtualbox.org/manual/ch06.html#network_bridged
>
> Regards,
> --
> -Chuck
>
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

no servers found

2014-08-19 Thread Adamiec, Lawrence
HI,

I am running BIND 9.6-ESV-R5-P1 on a Solaris 10 server.  I can run queries
without specifying a name server on my Solaris servers successfully.  When
I try to run a query on a Solaris 10 virtual server, I get "connection
timed out; no servers could be reached" error.

If I add the name servers from our main campus (or 8.8.8.8) to the virtual
server's resolv.conf file, then dig will use the other name server and skip
my name server to resolve the query which is successful.

If i use dig and specify my master name server, then the query works fine.

I do not understand why the virtual server cannot find the name servers on
my campus (my building) unless I specify it.


Host file contents of virtual server
#
# Internet host table
#
::1 localhost
127.0.0.1   localhost
64.131.119.61   dnstest.kentlaw.edu dnstest loghost
64.131.119.11   nsa.kentlaw.edu nsa
64.131.119.12   nsb.kentlaw.edu nsb


resolv.conf contents of virtual server

domain kentlaw.edu
nameserver 66.131.119.11
nameserver 66.131.119.12
nameserver 216.47.128.11
nameserver 216.47.128.12
nameserver 8.8.8.8
search kentlaw.edu


Larry

Lawrence Adamiec
UNIX Mgr/Web Support Specialist
Illinois Institute of Technology-DTC
565  W. Adams St.
Chicago, IL
60661
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: Weird dig behavior when querying ANY

2013-09-10 Thread Adamiec, Lawrence
I don't get 5 seconds for a reply.


;; ANSWER SECTION:
google.com. 219 IN  2607:f8b0:4009:805::1006
google.com. 29  IN  A   173.194.46.34
google.com. 29  IN  A   173.194.46.35
google.com. 29  IN  A   173.194.46.36
google.com. 29  IN  A   173.194.46.37
google.com. 29  IN  A   173.194.46.38
google.com. 29  IN  A   173.194.46.39
google.com. 29  IN  A   173.194.46.40
google.com. 29  IN  A   173.194.46.41
google.com. 29  IN  A   173.194.46.46
google.com. 29  IN  A   173.194.46.32
google.com. 29  IN  A   173.194.46.33
google.com. 33272   IN  NS  ns4.google.com.
google.com. 33272   IN  NS  ns2.google.com.
google.com. 33272   IN  NS  ns1.google.com.
google.com. 33272   IN  NS  ns3.google.com.



Larry




On Tue, Sep 10, 2013 at 10:40 AM, Nicholas F Miller <
nicholas.mil...@colorado.edu> wrote:

> The problem is the reply will ALWAYS be five seconds when doing an 'ANY'
> query. It is not a matter of the TTL counting down.
> _
> Nicholas Miller, OIT, University of Colorado at Boulder
>
>
>
>
> On Sep 10, 2013, at 9:24 AM, Matus UHLAR - fantomas 
> wrote:
>
> > On 10.09.13 08:15, Nicholas F Miller wrote:
> >> I am at a loss. When doing digs using our name servers for 'ANY'
> records of
> >> a domain we are getting TTLs of five seconds.  The TTLs will be correct
> if
> >> we query for the records individually just not when using 'ANY'.  Ideas?
> >
> > BIND simply provides you the remaining TTL. If you do it again, you will
> see
> > TTL has either decreased in the time difference, or the records were
> fetched
> > again.
> >
> > the discussion a few days ago has revealed that BIND does not recursively
> > fetch records when you send ANY query.
> > --
> > Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/
> > Warning: I wish NOT to receive e-mail advertising to this address.
> > Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
> > "They say when you play that M$ CD backward you can hear satanic
> messages."
> > "That's nothing. If you play it forward it will install Windows."
> > ___
> > Please visit https://lists.isc.org/mailman/listinfo/bind-users to
> unsubscribe from this list
> >
> > bind-users mailing list
> > bind-users@lists.isc.org
> > https://lists.isc.org/mailman/listinfo/bind-users
>
> ___
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to
> unsubscribe from this list
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

another performance tuning question

2012-11-30 Thread Adamiec, Lawrence
I must be doing something wrong.  I ran queryperf and the results don't
look right, 13 and 23 queries per second?  What am I doing wrong?  I ran
the queryperf on the same machine that is running BIND.  I got similar
results when running against the master server.

I ran the test one right after the other and here are the results.

Statistics:

  Parse input file: once
  Ended due to: reaching end of file

  Queries sent: 11000 queries
  Queries completed:8968 queries
  Queries lost: 2032 queries
  Queries delayed(?):   0 queries

  RTT max:  4.868892 sec
  RTT min:  0.22 sec
  RTT average:  0.327400 sec
  RTT std deviation:0.806941 sec
  RTT out of range: 0 queries

  Percentage completed:  81.53%
  Percentage lost:   18.47%

  Started at:   Fri Nov 30 14:18:21 2012
  Finished at:  Fri Nov 30 14:29:23 2012
  Ran for:  662.497398 seconds

  Queries per second:   13.536657 qps

#
Statistics:

  Parse input file: once
  Ended due to: reaching end of file

  Queries sent: 11000 queries
  Queries completed:9797 queries
  Queries lost: 1203 queries
  Queries delayed(?):   0 queries

  RTT max:  5.042038 sec
  RTT min:  0.35 sec
  RTT average:  0.240968 sec
  RTT std deviation:0.721397 sec
  RTT out of range: 1 queries

  Percentage completed:  89.06%
  Percentage lost:   10.94%

  Started at:   Fri Nov 30 14:35:53 2012
  Finished at:  Fri Nov 30 14:42:57 2012
  Ran for:  423.880459 seconds

  Queries per second:   23.112648 qps


Larry
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: Performance tuning

2012-11-27 Thread Adamiec, Lawrence
Hi,

My original post was about writing a report to optimize our DNS servers and
the report needed to address two questions.  Based on the answers I
received, I will write our servers are already optimized and no further
tuning is needed.

Now about the two specific questions for the report.

Q1 --  I don't believe the problem is DNS related.  However, I have not
been able to recreate the trouble so I don't know if there is any problem.
 As other list members have posted, they didn't have any problems with the
pages rendering either.  As far as asking me about the web sites staff,
well, I am the technical contact for our web sites.  Our Public Affairs
department handles content related issues and I take of all server related
things.  I will double check the web server, but it shouldn't be using any
rewrites for the main page.  And I don't know who is complaining about the
pages.  This question came from my boss.

Q2 --  The forwarders statement was added to our config file about six
years ago.  Some users complained they could not reach two or three
specific web sites outside our domain.  At that time, one of our network
staff members told me his nslookup for the sites were timing out.  I was
instructed to insert the forwarder statement with the main campus servers
acting as the forwarder.  The time outs stopped and people stopped
complaining.  I don't know that adding the forwarder statement actually
fixed any trouble but nslookups did not time out, people stopped
complaining, and my boss was happy.  (I know dig is better).
 Unfortunately, I don't remember which sites people were complaining about.


Larry



On Tue, Nov 27, 2012 at 8:11 AM,  wrote:

> "Adamiec, Lawrence"  wrote on 11/26/2012
> 01:12:48 PM:
>
>
> > To the best of my knowledge, there are no problems with our DNS.  We
> > only host 25 domains.
> >
> > The report must also address these two specific questions:
> >
> > 1. Why does www.kentlaw.iit.edu load quicker than kentlaw.iit.edu in
> > any browser?
>
> Are you sure this is a DNS issue?  Test it by adding both to /etc/hosts
> (or Windows equal).   Reboot and flush all caches between tests.
>
> > 2. What happens if we remove the forwarders option from named.conf?
>
> Depends why you have the forwarders.
> .
> > I can't duplicate the issue in Q1 and I'm trying to determine a way
> > of testing Q2.
>
> Oh the joys of intermittent problems. Are you sure the issues reported as
> Q1 are real?  Have the web site folks been involved in discussions or are
> they just blaming DNS without testing anything?
>
> If possible sneak host file entries onto a handful of user machines and
> see if they still complain.
>
>
>
>
>
> Confidentiality Notice:
> This electronic message and any attachments may contain confidential or
> privileged information, and is intended only for the individual or entity
> identified above as the addressee. If you are not the addressee (or the
> employee or agent responsible to deliver it to the addressee), or if this
> message has been addressed to you in error, you are hereby notified that
> you may not copy, forward, disclose or use any part of this message or any
> attachments. Please notify the sender immediately by return e-mail or
> telephone and delete this message from your system.
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: Performance tuning

2012-11-26 Thread Adamiec, Lawrence
Thanks to everyone who replied.


Larry



On Mon, Nov 26, 2012 at 1:25 PM, Leonardo Santagostini <
lsantagost...@gmail.com> wrote:

> I see no problems.
>
> [ec2-user@domU-12-31-39-06-2E-64 ~]$ time dig www.kentlaw.iit.edu
>
> ; <<>> DiG 9.7.0-P2-RedHat-9.7.0-5.P2.6.amzn1 <<>> www.kentlaw.iit.edu
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54160
> ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
>
> ;; QUESTION SECTION:
> ;www.kentlaw.iit.edu.   IN  A
>
> ;; ANSWER SECTION:
> www.kentlaw.iit.edu.86400   IN  A   64.131.119.9
>
> ;; Query time: 847 msec
> ;; SERVER: 200.51.197.187#53(200.51.197.187)
> ;; WHEN: Mon Nov 26 19:23:46 2012
> ;; MSG SIZE  rcvd: 53
>
>
> *real0m0.854s*
> user0m0.000s
> sys 0m0.008s
> [ec2-user@domU-12-31-39-06-2E-64 ~]$ time dig kentlaw.iit.edu
>
> ; <<>> DiG 9.7.0-P2-RedHat-9.7.0-5.P2.6.amzn1 <<>> kentlaw.iit.edu
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39163
> ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
>
> ;; QUESTION SECTION:
> ;kentlaw.iit.edu.   IN  A
>
> ;; ANSWER SECTION:
> kentlaw.iit.edu.86400   IN  A   64.131.119.9
>
> ;; Query time: 780 msec
> ;; SERVER: 200.51.197.187#53(200.51.197.187)
> ;; WHEN: Mon Nov 26 19:24:11 2012
> ;; MSG SIZE  rcvd: 49
>
>
> *real0m0.799s*
> user0m0.004s
> sys 0m0.016s
> [ec2-user@domU-12-31-39-06-2E-64 ~]$
>
> Hope that helps.
>
> regards
> Saludos.-
> Leonardo Santagostini
>
> <http://ar.linkedin.com/in/santagostini>
>
>
>
>
>
>
> 2012/11/26 Chuck Swiger 
>
>> Hi--
>>
>> On Nov 26, 2012, at 10:12 AM, Adamiec, Lawrence wrote:
>> > The report must also address these two specific questions:
>> >
>> >   • Why does www.kentlaw.iit.edu load quicker than kentlaw.iit.eduin 
>> > any browser?
>> >   • What happens if we remove the forwarders option from named.conf?
>> > I can't duplicate the issue in Q1 and I'm trying to determine a way of
>> testing Q2.
>>
>> Q1 isn't related to DNS performance; both of the names you mention
>> resolve to the same IP address via an A record.  There wasn't a significant
>> difference in response time I saw by loading the webpages (both took ~1.3 s
>> per curl), but one likely could improve webserver performance by running
>> Apache, nginx, or almost anything else instead of than Microsoft's IIS.
>>
>> The domain seems to be missing A records for your nameservers, however:
>>
>>   http://www.dnsvalidation.com/reports/50b3b5167d79ee02b826
>>
>> As for Q2, it depends on whether the nameservers you are pointing to do
>> better in caching queries then your local nameservers would doing recursive
>> lookups for themselves.  If the local nameservers have poor connectivity
>> compared to the forwarders, maybe, otherwise it's probably not helpful to
>> use forwarders.
>>
>> Regards,
>> --
>> -Chuck
>>
>> ___
>> Please visit https://lists.isc.org/mailman/listinfo/bind-users to
>> unsubscribe from this list
>>
>> bind-users mailing list
>> bind-users@lists.isc.org
>> https://lists.isc.org/mailman/listinfo/bind-users
>>
>
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Re: Performance tuning

2012-11-26 Thread Adamiec, Lawrence
To the best of my knowledge, there are no problems with our DNS.  We only
host 25 domains.

The report must also address these two specific questions:


   1. Why does www.kentlaw.iit.edu load quicker than kentlaw.iit.edu in any
   browser?
   2. What happens if we remove the forwarders option from named.conf?

I can't duplicate the issue in Q1 and I'm trying to determine a way of
testing Q2.

Larry


On Mon, Nov 26, 2012 at 11:39 AM, Doug Barton  wrote:

> What a delightfully vague requirement. :)
>
> I would push back a bit on exactly what problems are attempted to be
> solved here. The BIND defaults are about as efficient as they can be,
> especially so in later versions.
>
> Doug
>
>
> On 11/26/2012 11:01 AM, Adamiec, Lawrence wrote:
> > Hi,
> >
> > I have been tasked with authoring a DNS report "to achieve optimal
> > performance."  The report must include:
> >
> > CPU usage
> > memory usage
> > bandwidth usage
> > throughput
> > latency
> >
> > I have found some information regarding the number of queries processed
> > per minute but nothing of value for the above areas.
> >
> > Is there some documentation that discusses the above areas?
> >
> > We are running BIND 9.6-ESV-R5-P1, Solaris 10 on a SPARC server.  My
> > report will include the fact we must upgrade from BIND 9.6-ESV-R5-P1
> >
> > Thank you in advance.
> >
> > Larry
> >
> > Lawrence Adamiec
> > UNIX Mgr
> > IIT Chicago-Kent College of Law
>
>
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Performance tuning

2012-11-26 Thread Adamiec, Lawrence
Hi,

I have been tasked with authoring a DNS report "to achieve optimal
performance."  The report must include:

CPU usage
memory usage
bandwidth usage
throughput
latency

I have found some information regarding the number of queries processed per
minute but nothing of value for the above areas.

Is there some documentation that discusses the above areas?

We are running BIND 9.6-ESV-R5-P1, Solaris 10 on a SPARC server.  My report
will include the fact we must upgrade from BIND 9.6-ESV-R5-P1

Thank you in advance.

Larry

Lawrence Adamiec
UNIX Mgr
IIT Chicago-Kent College of Law
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

RE: recursion and forwarding

2012-01-12 Thread Adamiec, Lawrence
This is a very good explanation.  Thank you for your help.

Larry


> -Original Message-
> From: bind-users-bounces+ladamiec=kentlaw@lists.isc.org
[mailto:bind-users-
> bounces+ladamiec=kentlaw@lists.isc.org] On Behalf Of Phil Mayers
> Sent: Thursday, January 12, 2012 12:35
> To: bind-users@lists.isc.org
> Subject: Re: recursion and forwarding
> 
> On 01/12/2012 06:15 PM, Adamiec, Lawrence wrote:
> 
> > So when does recursion occur, before the query is forwarded or
never? I
> > thought recursion was supposed to go looking for the answers. If
> > recursion does not return an answer then does the query get
forwarded?
> 
> "forwarders" IIRC works as follows:
> 
>   1. If query answer in cache, reply from cache to client, stop
>   2. Send query to forwarders
>   3. If reply, add to cache, reply to client, stop
>   4. No reply: if "forward only" set, error to client, stop
>   5. Perform normal recursion
> 
> That is - it tries cache, then the forwarders, then does recursion
> itself (unless "forward only" is set).
> ___
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to
unsubscribe from this list
> 
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


recursion and forwarding

2012-01-12 Thread Adamiec, Lawrence
Hi,

 

I am running one master server and one slave server with BIND 9.6.1-P3.
The global options section on both servers are identical.

 

In the options section I have,

allow-recursion { ck_domain; };

forwarders { 216.47.128.11; 216.47.128.12; 216.47.143.90; };

 

The ck_domain ACL contains internal IPs only.

 

The documentation I have read states that forwarders will forward a
client's query if the answer is not in the server's cache and the server
does not know the answer. 

 

So when does recursion occur, before the query is forwarded or never?  I
thought recursion was supposed to go looking for the answers.  If
recursion does not return an answer then does the query get forwarded?

 

Larry Adamiec

UNIX Mgr.

312-906-5301

 

___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

RE: Help with dig to check NS servers for DNSSEC setup

2011-11-14 Thread Adamiec, Lawrence
Here are some results using the same commands you used.



# dig bonsi.org

; <<>> DiG 9.6.1-P3 <<>> bonsi.org
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 1462
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;bonsi.org. IN  A

;; Query time: 666 msec
;; SERVER: 64.131.119.11#53(64.131.119.11)
;; WHEN: Mon Nov 14 14:41:54 2011
;; MSG SIZE  rcvd: 27



# dig @63.200.45.18 ns1.bonsi.org soa

; <<>> DiG 9.6.1-P3 <<>> @63.200.45.18 ns1.bonsi.org soa
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 986
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;ns1.bonsi.org. IN  SOA

;; Query time: 75 msec
;; SERVER: 63.200.45.18#53(63.200.45.18)
;; WHEN: Mon Nov 14 14:42:25 2011
;; MSG SIZE  rcvd: 31

#

> -Original Message-
> From: bind-users-bounces+ladamiec=kentlaw@lists.isc.org
[mailto:bind-users-
> bounces+ladamiec=kentlaw@lists.isc.org] On Behalf Of Eduardo Bonsi
> Sent: Monday, November 14, 2011 14:39
> To: bind-us...@isc.org
> Subject: Help with dig to check NS servers for DNSSEC setup
> 
> I am checking my DNS setup from inside using dig and I am getting
> everything ok but I need a second opinion from outside of the server
to
> see if my ns1 and ns2 are responding ok to setup DNSSEC.
> 
> Thanks!
> 
> user:~ user1$ dig bonsi.org
> 
> ; <<>> DiG 9.6-ESV-R4-P3 <<>> bonsi.org
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35880
> ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 1
> ;; WARNING: recursion requested but not available
> 
> ;; QUESTION SECTION:
> ;bonsi.org.   IN  A
> 
> ;; ANSWER SECTION:
> bonsi.org.3600IN  A   63.200.45.21
> 
> ;; AUTHORITY SECTION:
> bonsi.org.3600IN  NS  ns2.bonsi.org.
> bonsi.org.3600IN  NS  ns1.bonsi.org.
> 
> ;; ADDITIONAL SECTION:
> ns2.bonsi.org.3600IN  A   63.200.45.19
> 
> ;; Query time: 14 msec
> ;; SERVER: 63.200.45.18#53(63.200.45.18)
> ;; WHEN: Mon Nov 14 12:09:43 2011
> ;; MSG SIZE  rcvd: 95
> 
> user:~ user1$ dig @63.200.45.18 ns1.bonsi.org soa
> 
> ; <<>> DiG 9.6-ESV-R4-P3 <<>> @63.200.45.18 ns1.bonsi.org soa
> ; (1 server found)
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31586
> ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0
> ;; WARNING: recursion requested but not available
> 
> ;; QUESTION SECTION:
> ;ns1.bonsi.org.   IN  SOA
> 
> ;; ANSWER SECTION:
> ns1.bonsi.org.3600IN  SOA ns1.bonsi.org.
hostmaster.bonsi.org.
> 2011101403 10800 3600 604800 3600
> 
> ;; AUTHORITY SECTION:
> ns1.bonsi.org.3600IN  NS  ns1.bonsi.org.
> 
> ;; Query time: 14 msec
> ;; SERVER: 63.200.45.18#53(63.200.45.18)
> ;; WHEN: Mon Nov 14 12:10:19 2011
> ;; MSG SIZE  rcvd: 92
> 
> user:~ user1$ dig @63.200.45.19 ns2.bonsi.org
> 
> ; <<>> DiG 9.6-ESV-R4-P3 <<>> @63.200.45.19 ns2.bonsi.org
> ; (1 server found)
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38660
> ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0
> ;; WARNING: recursion requested but not available
> 
> ;; QUESTION SECTION:
> ;ns2.bonsi.org.   IN  A
> 
> ;; ANSWER SECTION:
> ns2.bonsi.org.3600IN  A   63.200.45.19
> 
> ;; AUTHORITY SECTION:
> ns2.bonsi.org.3600IN  NS  ns2.bonsi.org.
> 
> ;; Query time: 12 msec
> ;; SERVER: 63.200.45.19#53(63.200.45.19)
> ;; WHEN: Mon Nov 14 12:11:04 2011
> ;; MSG SIZE  rcvd: 61
> 
> user:~ user1$ dig @63.200.45.19 ns2.bonsi.org soa
> 
> ; <<>> DiG 9.6-ESV-R4-P3 <<>> @63.200.45.19 ns2.bonsi.org soa
> ; (1 server found)
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 17334
> ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 1
> ;; WARNING: recursion requested but not available
> 
> ;; QUESTION SECTION:
> ;ns2.bonsi.org.   IN  SOA
> 
> ;; ANSWER SECTION:
> ns2.bonsi.org.3600IN  SOA ns2.bonsi.org.
hostmaster.bonsi.org.
> 2011101409 10800 3600 604800 3600
> 
> ;; AUTHORITY SECTION:
> ns2.bonsi.org.3600IN  NS  ns2.bonsi.org.
> 
> ;; ADDITIONAL SECTION:
> ns2.bonsi.org.3600IN  A   63.200.45.19
> 
> ;; Query time: 58 msec
> ;; SERVER: 63.200.45.19#53(63.2

RE: One IP in multiple zones

2011-09-23 Thread Adamiec, Lawrence
Thanks to everyone for the help.

Larry

> > On Sep 21, 2011, at 3:56 PM, Adamiec, Lawrence wrote:
> >
> > > Hi,
> > >
> > > Is it possible to have one IP in multiple zone files for forward
lookups? What type of troubles would be encountered?
> > > Larry
> > >
> > > Lawrence Adamiec
> > > Unix Manager/Web Support Specialist
> > > Center for Law and Computers
> > > Chicago-Kent College of Law
> > > Illinois Institute of Technology
> > > Room 525B
> > > 565 W. Adams St.
> > > Chicago, Illinois
> > > 60661
> > >
> > > ___
> > > Please visit https://lists.isc.org/mailman/listinfo/bind-users to
unsubscribe from this list
> > >
> > > bind-users mailing list
> > > bind-users@lists.isc.org
> > > https://lists.isc.org/mailman/listinfo/bind-users

___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


RE: One IP in multiple zones

2011-09-21 Thread Adamiec, Lawrence
What I am looking at doing is the following.

www.existingdomain.edu  86400 A 192.0.0.1

www.existingdomain.newdomain.edu 86400 A 192.0.0.1

Larry


> -Original Message-
> From: Warren Kumari [mailto:war...@kumari.net]
> Sent: Wednesday, September 21, 2011 15:18
> To: Adamiec, Lawrence
> Cc: Warren Kumari; bind-users@lists.isc.org
> Subject: Re: One IP in multiple zones
> 
> 
> On Sep 21, 2011, at 3:56 PM, Adamiec, Lawrence wrote:
> 
> > Hi,
> >
> > Is it possible to have one IP in multiple zone files for forward
lookups?
> Yup, happens all the time:
> 
> example.com:
> www.example.com.   600   IN A  192.0.2.1
> 
> example.net:
> www.example.net.   600   IN A   192.0.2.1
> 
> foo:
> www.foo.com.  600IN A192.0.2.1
> 
> 
> > What type of troubles would be encountered?
> 
> That all depends on how you are trying to use it -- when an
application looks up the label it
> is presumably going to so something like connect to it, and the server
is going to have to
> know how to respond.
> 
> For example, if this is a web-server it will need to have virtual
hosts configured to is can
> respond as example.com / example.net / foo.com, etc.
> 
> If a mail server, it will need to know what all domains it handles
mail for (aliases file, etc)
> 
> W
> 
> 
> > Larry
> >
> > Lawrence Adamiec
> > Unix Manager/Web Support Specialist
> > Center for Law and Computers
> > Chicago-Kent College of Law
> > Illinois Institute of Technology
> > Room 525B
> > 565 W. Adams St.
> > Chicago, Illinois
> > 60661
> >
> > ___
> > Please visit https://lists.isc.org/mailman/listinfo/bind-users to
unsubscribe from this list
> >
> > bind-users mailing list
> > bind-users@lists.isc.org
> > https://lists.isc.org/mailman/listinfo/bind-users

___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


One IP in multiple zones

2011-09-21 Thread Adamiec, Lawrence
Hi,

 

Is it possible to have one IP in multiple zone files for forward
lookups?  What type of troubles would be encountered?

 

Larry

 

Lawrence Adamiec

Unix Manager/Web Support Specialist

Center for Law and Computers

Chicago-Kent College of Law

Illinois Institute of Technology

Room 525B

565 W. Adams St.

Chicago, Illinois

60661

 

___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users