Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Mike Hammett via Af
t: Friday, October 3, 2014 1:28:21 PM Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus If you're an ISP and you run back-end infrastructure on Windows, I feel sorry for you On Fri, Oct 3, 2014 at 11:23 AM, That One Guy via Af < af@afmug.com > wrote: si

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Eric Kuhnke via Af
https://kb.isc.org/article/AA-00913/0/BIND-9-Security-Vulnerability-Matrix.html >>>> >>>> ISC shows 9.8.8 EOL as of September 2014, so 9.8.2 is quite a few >>>> versions old. With all the DNS amplification attacks and these zero day >>>> exploits coming

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread That One Guy via Af
Oct 3, 2014 at 9:57 AM, Ken Hohhof via Af wrote: >> >>> I don’t think so. >>> >>> *From:* Adam Moffett via Af >>> *Sent:* Friday, October 03, 2014 8:34 AM >>> *To:* af@afmug.com >>> *Subject:* Re: [AFMUG] DNS server for guys who dont w

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Nicholas Eastman via Af
t to be pretty current, plus I >> believe 9.10 gives you RRL in your toolbox to deal with attacks although >> I’ll admit I haven’t had time to experiment with it. >> >> >> *From:* Mike Hammett via Af >> *Sent:* Friday, October 03, 2014 6:10 AM >> *To:*

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Mike Hammett via Af
October 3, 2014 8:30:01 AM Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus I would disagree, didn’t Steve say the latest he updated to was 9.8.2? https://kb.isc.org/article/AA-00913/0/BIND-9-Security-Vulnerability-Matrix.html ISC shows 9.8.8 EOL as of September 2014, so 9

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Paul McCall via Af
One time cost From: Af [mailto:af-boun...@afmug.com] On Behalf Of Adam Moffett via Af Sent: Friday, October 03, 2014 11:13 AM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus simpleDNS looks cheap. Is that a one time cost or do they do something recurring

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Adam Moffett via Af
afmug.com <mailto:af-boun...@afmug.com>] *On Behalf Of *Josh Baird via Af *Sent:* Friday, October 03, 2014 9:47 AM *To:* af@afmug.com <mailto:af@afmug.com> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus Yeah. RHEL/CentOS backport security patc

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread David via Af
o:af-boun...@afmug.com <mailto:af-boun...@afmug.com>] *On Behalf Of *Josh Baird via Af *Sent:* Friday, October 03, 2014 9:47 AM *To:* af@afmug.com <mailto:af@afmug.com> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus Yeah. RHEL/CentOS backport securi

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Josh Baird via Af
r EL. On Fri, Oct 3, 2014 at 9:57 AM, Ken Hohhof via Af wrote: > I don’t think so. > > *From:* Adam Moffett via Af > *Sent:* Friday, October 03, 2014 8:34 AM > *To:* af@afmug.com > *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus > > It may be 9.8

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Ty Featherling via Af
ally are > close to current regarding security updates even if they don't have the > latest version. > > > > - > Mike Hammett > Intelligent Computing Solutions > http://www.ics-il.com > > > -- > > *From: *"Ken Hohhof via Af" > *To: *af@

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread David via Af
*Sent:* Friday, October 03, 2014 6:10 AM *To:* af@afmug.com <mailto:af@afmug.com> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus The server based distributions like CentOS\RHEL and Debian generally are close to current regarding security updates

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Ken Hohhof via Af
I don’t think so. From: Adam Moffett via Af Sent: Friday, October 03, 2014 8:34 AM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus It may be 9.8.2 with security fixes backported from later versions. I would disagree, didn’t Steve say the latest he

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Paul McCall via Af
I think a couple of us has mentioned SimpleDNS – 2 minute install – just works ☺ From: Af [mailto:af-boun...@afmug.com] On Behalf Of Josh Baird via Af Sent: Friday, October 03, 2014 9:47 AM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus Yeah. RHEL/CentOS

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Josh Baird via Af
ives you RRL in your toolbox to deal with attacks although I’ll admit I > haven’t had time to experiment with it. > > > *From:* Mike Hammett via Af > *Sent:* Friday, October 03, 2014 6:10 AM > *To:* af@afmug.com > *Subject:* Re: [AFMUG] DNS server for guys who dont want to be

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Adam Moffett via Af
<mailto:af@afmug.com> *Sent:* Friday, October 03, 2014 6:10 AM *To:* af@afmug.com <mailto:af@afmug.com> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus The server based distributions like CentOS\RHEL and Debian generally are close to current regarding security updates

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Ken Hohhof via Af
l.com From: "Ken Hohhof via Af" To: af@afmug.com Sent: Thursday, October 2, 2014 5:30:01 PM Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus You need a named.conf that defines the slave zones and

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Mike Hammett via Af
ions http://www.ics-il.com - Original Message - From: "Timothy D. McNabb via Af" To: af@afmug.com Sent: Thursday, October 2, 2014 6:26:19 PM Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus I’ve never had a problem using yum and CentOS, you are right that

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-03 Thread Mike Hammett via Af
Hohhof via Af" To: af@afmug.com Sent: Thursday, October 2, 2014 5:30:01 PM Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus You need a named.conf that defines the slave zones and the IP address of the master. But first step is to download/compile/install the latest

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
that include a DNS server >> and management tool, at least for authoritative DNS? >> >> *From:* Josh Baird via Af >> *Sent:* Thursday, October 02, 2014 9:19 PM >> *To:* af@afmug.com >> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus >>

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread George Skorup (Cyber Broadcasting) via Af
* Thursday, October 02, 2014 9:19 PM *To:* af@afmug.com <mailto:af@afmug.com> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus There probably isn't. Use CentOS. Josh On Thu, Oct 2, 2014 at 9:34 PM, That One Guy via Af mailto:af@afmug.com>> wro

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
nt:* Thursday, October 02, 2014 9:19 PM > *To:* af@afmug.com > *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus > > There probably isn't. Use CentOS. > > Josh > > On Thu, Oct 2, 2014 at 9:34 PM, That One Guy via Af wrote: > >> I dont want bleedin

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Reggie Darden via Af
looks like 9.8.8 is EOL last month, so i see what you guys are saying >>>> about being behind >>>> 9.9.6 and 9.10.1 are both listed as current and stable, but 9.9.6 says >>>> Extended Support Version, what does that mean? >>>> >>>>> On

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
ustomer to do that. > > Steve, didn’t you say you had cPanel? Doesn’t that include a DNS server > and management tool, at least for authoritative DNS? > > *From:* Josh Baird via Af > *Sent:* Thursday, October 02, 2014 9:19 PM > *To:* af@afmug.com > *Subject:* Re: [AFMUG]

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread George Skorup (Cyber Broadcasting) via Af
lt;mailto:af@afmug.com> *Sent:* Thursday, October 02, 2014 9:19 PM *To:* af@afmug.com <mailto:af@afmug.com> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus There probably isn't. Use CentOS. Josh On Thu, Oct 2, 2014 at 9:34 PM, That One Guy via Af <mailto:af@afmug.c

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
and management tool, at least for authoritative DNS? > > *From:* Josh Baird via Af > *Sent:* Thursday, October 02, 2014 9:19 PM > *To:* af@afmug.com > *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus > > There probably isn't. Use CentOS. > > Josh >

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Ken Hohhof via Af
: Josh Baird via Af Sent: Thursday, October 02, 2014 9:19 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus There probably isn't. Use CentOS. Josh On Thu, Oct 2, 2014 at 9:34 PM, That One Guy via Af wrote: I dont want bleeding edge, I like stable, a

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Josh Baird via Af
see what you guys are >>> saying about being behind >>> 9.9.6 and 9.10.1 are both listed as current and stable, but 9.9.6 says >>> Extended Support Version, what does that mean? >>> >>> On Thu, Oct 2, 2014 at 7:51 PM, That One Guy via Af >>> wr

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Ken Hohhof via Af
I think the main new feature in 9.10 is response rate limiting. From: Josh Baird via Af Sent: Thursday, October 02, 2014 8:08 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus You can if you use third party packages, but you don't need to unless you ne

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Ken Hohhof via Af
Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus I already have installed bind through webmin, it is a newer version, just by a couple revisions but the ubuntu one wont update any more its BIND version 9.8.2 I can manually add the slave zone and test the transfer it

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
ume i cant update BIND beyong releases specific to CentOS? >>> >>> On Thu, Oct 2, 2014 at 7:28 PM, Ken Hohhof via Af wrote: >>> >>>> My BIND servers are on 9.10.0-P2. >>>> >>>> *From:* That One Guy via Af >>>> *Sent:* Thu

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Josh Baird via Af
PM, That One Guy via Af wrote: > >> i assume i cant update BIND beyong releases specific to CentOS? >> >> On Thu, Oct 2, 2014 at 7:28 PM, Ken Hohhof via Af wrote: >> >>> My BIND servers are on 9.10.0-P2. >>> >>> *From:* That One Guy via Af >>

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
>> My BIND servers are on 9.10.0-P2. >> >> *From:* That One Guy via Af >> *Sent:* Thursday, October 02, 2014 6:10 PM >> *To:* af@afmug.com >> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus >> >> I already have installed bin

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Josh Baird via Af
PM >> *To:* af@afmug.com >> *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus >> >> I already have installed bind through webmin, it is a newer version, >> just by a couple revisions but the ubuntu one wont update any more >> its BIND version 9.8

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
ant the latest BIND. You might then want to >> lock out the package from being updated by yum. >> >> >> *From:* That One Guy via Af >> *Sent:* Thursday, October 02, 2014 4:36 PM >> *To:* af@afmug.com >> *Subject:* Re: [AFMUG] DNS server for guys who

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Ken Hohhof via Af
My BIND servers are on 9.10.0-P2. From: That One Guy via Af Sent: Thursday, October 02, 2014 6:10 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus I already have installed bind through webmin, it is a newer version, just by a couple revisions but the

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Josh Baird via Af
that allows only our 3 /22’s to talk to them via udp. > > > > AFAIK the package for system-config-bind is still non-existent as of this > writing for CentOS 6. > > > > -Tim > > > > > > *From:* Af [mailto:af-boun...@afmug.com] *On Behalf Of *That One Guy v

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Timothy D. McNabb via Af
the package for system-config-bind is still non-existent as of this writing for CentOS 6. -Tim From: Af [mailto:af-boun...@afmug.com] On Behalf Of That One Guy via Af Sent: Thursday, October 02, 2014 4:10 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus I

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
ne Guy via Af > *Sent:* Thursday, October 02, 2014 4:36 PM > *To:* af@afmug.com > *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus > > So Im at a new Centos with webmin fresh bind install. > We have one master, one slave server > I have never set up bind,

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Ken Hohhof via Af
few steps behind. Given the DNS attacks, you want the latest BIND. You might then want to lock out the package from being updated by yum. From: That One Guy via Af Sent: Thursday, October 02, 2014 4:36 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus So

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
14 2:24 PM > *To:* af@afmug.com > *Subject:* Re: [AFMUG] DNS server for guys who dont want to be gurus > > > > 2 questions in this > > 1. when running through the current centos installation, what do i select > for the server type, for powercode it says select basic serve

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Paul Stewart via Af
] On Behalf Of That One Guy via Af Sent: Thursday, October 02, 2014 2:24 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus 2 questions in this 1. when running through the current centos installation, what do i select for the server type, for powercode it

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Paul Stewart via Af
, 2014 2:25 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus You want to have domain level control for individual users.. webmin isn't the best in that arena but if you're not adverse to spending a small amount of money, take a look at Virtualmin.

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Kerry via Af
guys who dont want to be gurus BIND is your friend. i'd also set iptables to only allow queries from your network. On Thu, Oct 2, 2014 at 11:20 AM, That One Guy via Af <mailto:af@afmug.com>> wrote: Is there a good, simple package for locally hosted DNS Servers for people like me

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Christopher Tyler via Af
, 2014 1:13:01 PM Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus CentOS+BIND+Webmin :) I can’t remember but Usermin might be the part you’re looking for specific to users updating their own DNS….. From: Af [mailto:af-boun...@afmug.com] On Behalf Of That One Guy via A

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
g.com] *On Behalf Of *That One Guy via > Af > *Sent:* Thursday, October 02, 2014 1:21 PM > *To:* af@afmug.com > *Subject:* [AFMUG] DNS server for guys who dont want to be gurus > > > > Is there a good, simple package for locally hosted DNS Servers for people > like me

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Paul Stewart via Af
server for guys who dont want to be gurus Is there a good, simple package for locally hosted DNS Servers for people like me who dont want to get too far into managing the linux at a granular level? we are used to the webmin interface. It would be nice if it had the option to set up client

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Timothy D. McNabb via Af
Sent: Thursday, October 02, 2014 10:49 AM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus not just iptables, you can do it in bind9 in your named.conf.options: acl allowedclients { 10.20.20.0/24<http://10.20.20.0/24>; localhost; localnets; }; put your dif

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
I guess I should be asking, how do I replicate my environment to newer OS This is an old Ubuntu server running BIND version 9.4.2 on webmin 1.710 >From the webmin interface is there a simple way to export the bind configuration to import cleanly into a new server We use CentOS for our billing serv

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Mark - Myakka Technologies via Af
If you are more comfortable in the windows world, try http://www.simpledns.com/ -- Best regards, Markmailto:m...@mailmt.com Myakka Technologies, Inc. www.MyakkaTech.com Proud Sponsor of the Myakka City Relay For Life http://www.RelayForLife.org/MyakkaCityFL Pleas

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
This is a BIND dns server using webmin interface when you say edit the file, that goes beyond what I want to do, I like using the GUI from webmin I like GUIs, because they remind me that I am incompetent, this helps to keep me grounded and less cocky On Thu, Oct 2, 2014 at 12:49 PM, Eric Kuhnke v

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Eric Kuhnke via Af
not just iptables, you can do it in bind9 in your named.conf.options: acl allowedclients { 10.20.20.0/24; localhost; localnets; }; put your different netblocks in there, 10.20.20.0/24 is an example then further down in the same file, this is an example from my ns1 options { directory "/v

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Paul McCall via Af
SimpleDNS works great - 5+ years no issues -- SIMPLE From: Af [mailto:af-boun...@afmug.com] On Behalf Of Sean Heskett via Af Sent: Thursday, October 02, 2014 1:27 PM To: af@afmug.com Subject: Re: [AFMUG] DNS server for guys who dont want to be gurus BIND is your friend. i'd also set ipt

Re: [AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread Sean Heskett via Af
BIND is your friend. i'd also set iptables to only allow queries from your network. On Thu, Oct 2, 2014 at 11:20 AM, That One Guy via Af wrote: > Is there a good, simple package for locally hosted DNS Servers for people > like me who dont want to get too far into managing the linux at a granu

[AFMUG] DNS server for guys who dont want to be gurus

2014-10-02 Thread That One Guy via Af
Is there a good, simple package for locally hosted DNS Servers for people like me who dont want to get too far into managing the linux at a granular level? we are used to the webmin interface. It would be nice if it had the option to set up client accounts for some clients to manage their own DNS b