Re: Intermittent failures resolving .org domains in BIND 9.7.0 with DLV enabled

2010-03-30 Thread Matus UHLAR - fantomas
I have seen this happen when bind for some reason (eg mtu issues with vpn) cannot query for the DLV key at dlv.isc.org. I have not figured out the exact failure mode there. Check the logs to see errors for DNSKEY queries for dlv.isc.org to see if this is happening here too. However in

Re: invalid requests for dns_registration.*

2010-03-30 Thread Matus UHLAR - fantomas
In article mailman.974.1269852204.21153.bind-us...@lists.isc.org, Matus UHLAR - fantomas uh...@fantomas.sk wrote: on one of my nameservers I see many of these messages in log files: Mar 29 07:59:07 gtssk1 named[5012]: security: error: client 195.168.29.200#65293: view gtsi: check-names

Re: Intermittent failures resolving .org domains in BIND 9.7.0 with DLV enabled

2010-03-30 Thread Sam Wilson
In article mailman.983.1269884152.21153.bind-us...@lists.isc.org, Roy Badami r...@gnomon.org.uk wrote: I have seen this happen when bind for some reason (eg mtu issues with vpn) cannot query for the DLV key at dlv.isc.org. I have not figured out the exact failure mode there. Check the logs

problem with notifies

2010-03-30 Thread fddi
Hello I have a name server which is slave for many other zones. The problem is that I upgraded to bind 9.3.x and now I have plenty of messages like: IN: refused notify from non-master: itselfIPaddress how can I avoid this ? Do I ahev to insert notify no for every zone in which it is slave

Re: Same source port queries dropped by ServerIron load balancer

2010-03-30 Thread Tony Finch
On Tue, 30 Mar 2010, Abdulla Bushlaibi wrote: We are facing query drops by using dnsperf tool from ISC testing the DNS service via load balancer. Multiple queries from the same source port are being dropped partially by the load balancer and as per the load balancer vendor feed back, this is

any IPv6 ACL for BIND

2010-03-30 Thread ivan jr sy
hi all, is there a built-in ACL that represents any IPv6 connection? I have some experiment with allow-query { aclhere; }; where aclhere represents any IPv6 network, anywhere from the Internet. If there's no built-in, what is the best way to come up with an equivalent? Thanks!

Re: any IPv6 ACL for BIND

2010-03-30 Thread Evan Hunt
If there's no built-in, what is the best way to come up with an equivalent? I think this will work: acl any6 { ::0/0; }; acl any4 { 0.0.0.0/0; }; -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ bind-users mailing list

Re: problem with notifies

2010-03-30 Thread Matus UHLAR - fantomas
On 30.03.10 13:56, fddi wrote: Hello I have a name server which is slave for many other zones. The problem is that I upgraded to bind 9.3.x and now I have plenty of messages like: upgraded _to_ 9.3 ? 9.3 is obsolete for some time. IN: refused notify from non-master: itselfIPaddress how

Re: Same source port queries dropped by ServerIron load balancer

2010-03-30 Thread Kevin Darcy
On 3/30/2010 8:00 AM, Tony Finch wrote: On Tue, 30 Mar 2010, Abdulla Bushlaibi wrote: We are facing query drops by using dnsperf tool from ISC testing the DNS service via load balancer. Multiple queries from the same source port are being dropped partially by the load balancer and as per

Re: rndc: unsupported algorithm:

2010-03-30 Thread Warren Kumari
Try add this: options { default-key feld-server.feldland.lan.; default-server 127.0.0.1; default-port 953; }; On Mar 30, 2010, at 4:05 PM, Markus Feldmann wrote: I changed my key to key feld-server.feldland.lan. { algorithm hmac-md5; secret

Re: rndc: unsupported algorithm:

2010-03-30 Thread Kevin Darcy
On 3/30/2010 3:53 PM, Markus Feldmann wrote: Hi All, i tried to reload my config and zones with rndc. My Bind version is BIND 9.5.1-P3. My rndc.key looks like this. key feld-server.feldland.lan. { algorithm HMAC-MD5.SIG-ALG.REG.INT; secret TNCrihQV8NjY6bzA5GMJIg==; }; This is what i

MX records for new additional domain on existing authoritative name servers

2010-03-30 Thread Lear, Karen (Evolver)
I'm adding a new domain to my existing authoritative name servers, and need to add an MX record for a device on the existing domain. That device will serve both domains until we get a new box in and then we will have separate MX records/devices for each domain. I have created a new zone file

Re: rndc: unsupported algorithm:

2010-03-30 Thread Markus Feldmann
Kevin Darcy schrieb: On 3/30/2010 3:53 PM, Markus Feldmann wrote: Hi All, i tried to reload my config and zones with rndc. My Bind version is BIND 9.5.1-P3. My rndc.key looks like this. key feld-server.feldland.lan. { algorithm HMAC-MD5.SIG-ALG.REG.INT; secret

Re: MX records for new additional domain on existing authoritative name servers

2010-03-30 Thread Matthew Pounsett
Hi Karen. Please don't start a new thread by replying to an email in an existing discussion -- your message can get lost in that other discussion, rather than appearing as a new topic for anyone who threads their email. On 2010/03/30, at 16:30, Lear, Karen (Evolver) wrote: I'm adding a new

Re: Comprehension question to DDNS

2010-03-30 Thread Markus Feldmann
Hi Mark, i changed some configs and got on. Mar 30 22:50:45 feld-server dhcpd: DHCPRELEASE of 192.168.0.196 from 00:1d:92:ab:35:9f (feld-bert.feldland.lan) via br0 (found) Mar 30 22:50:50 feld-server dhcpd: DHCPDISCOVER from 00:1d:92:ab:35:9f via br0 Mar 30 22:50:51 feld-server dhcpd:

Using an MX record from a different domain

2010-03-30 Thread Lear, Karen (Evolver)
I'm adding a new domain to my existing authoritative name servers, and need to add an MX record for a device residing on existing domain. When I run named-checkzone, I get a message about the MX record being out of zone and not having an A record. However, at the end of my named-checkzone

Re: Using an MX record from a different domain

2010-03-30 Thread Fr34k
Hello, named-checkzone is warning you that the MX has a different FQDN than the zone it is in. This is fine so long as the out of zone MX record is valid, but named-checkzone wants you to know that it can't verify for sure. So, it is a heads up message and why the ultimate response is OK. I

Re: Using an MX record from a different domain

2010-03-30 Thread Matthew Pounsett
On 2010/03/30, at 16:57, Lear, Karen (Evolver) wrote: I'm adding a new domain to my existing authoritative name servers, and need to add an MX record for a device residing on existing domain. When I run named-checkzone, I get a message about the MX record being out of zone and not

Re: Using an MX record from a different domain

2010-03-30 Thread Paul Wouters
On Tue, 30 Mar 2010, Matthew Pounsett wrote: named-checkzone doesn't only check the internal consistency of a zone, it also tries to see that it is externally consistent. e.g. that names referred to in other zones also exist. I was amused the day that feature came in without me realising

how to read and answer to this mailing list

2010-03-30 Thread Markus Feldmann
Hi All, normally i am using the gmane mailing list server to post and read mails from mailing lists, but this mailing list doesn't appear in gmane. How to? Which newsgroupserver do use for this list? regards Markus ___ bind-users mailing list

Re: Subdomain delegation only returns SOA on dig

2010-03-30 Thread Matthew Pounsett
On 2010/03/29, at 15:34, Prabhat Rana wrote: Hello all, I'm running BIND 9.6.1-P1 on a Solaris box. This DNS (ns1.spx.net) is authoritative to domain spx.net (this is just example). And I'm trying to delegate nse.spx.net to ns1.nse.spx.net. I think I have configured correctly but when

Re: how to read and answer to this mailing list

2010-03-30 Thread Markus Feldmann
Warren Kumari schrieb: In the footer of every message lurks the following link: https://lists.isc.org/mailman/listinfo/bind-users Yes ... i read this but you can not answer a mail this way. regards Markus ___ bind-users mailing list

Re: how to read and answer to this mailing list

2010-03-30 Thread Markus Feldmann
Warren Kumari schrieb: In the footer of every message lurks the following link: https://lists.isc.org/mailman/listinfo/bind-users And i mean not this mailing list but the dhcp-users mailing list. ___ bind-users mailing list bind-users@lists.isc.org

Re: how to read and answer to this mailing list

2010-03-30 Thread Matthew Pounsett
On 2010/03/30, at 19:04, Markus Feldmann wrote: Warren Kumari schrieb: In the footer of every message lurks the following link: https://lists.isc.org/mailman/listinfo/bind-users Yes ... i read this but you can not answer a mail this way. You can answer an email this way. I'm not sure if

Zone transfer issues on new domain

2010-03-30 Thread Lear, Karen (Evolver)
Can you tell me why I'm getting the message below on my slave server after adding a master zone on the master server for usptoenews.gov: [kl...@dns2 logs]$ grep enews activity.log 30-Mar-2010 17:17:45.484 notify: notice: client 10.240.6.50#10738: received notify for zone 'usptoenews.gov': TSIG

Re: Zone transfer issues on new domain

2010-03-30 Thread Sten Carlsen
Did you add it to the slaves configuration? It does not get automagically added; so the slave gets a notify on a zone it can not serve as it is not in its config. On 31/03/10 2:14, Lear, Karen (Evolver) wrote: Can you tell me why I'm getting the message below on my slave server after adding a

Re: how to read and answer to this mailing list

2010-03-30 Thread Sten Carlsen
If you follow the link at the bottom of this mail, there is a link that will display all lists served by this mail list server. There are links to some dhcp lists also, if you need that. Select one of those and join the list. On 31/03/10 1:20, Matthew Pounsett wrote: On 2010/03/30, at 19:04,