Re: Dig for link-local

2013-03-22 Thread Carlos M. Martinez
link-locals are not that special, with the exception of the % decorator... other than that, they work exactly like any other address. Bind/Apache/ will listen on link locals and they can be used as route next-hops too. regards, ~Carlos On 3/22/13 1:13 PM, Kevin Darcy wrote: > I'm not sure what

Re: Dig for link-local

2013-03-22 Thread Carlos M. Martinez
Transport has nothing to do with content in DNS. If your client asks for an record it will get the appropriate answer according to the zone's records (a value or an error condition) regardless on whether the query was made over IPv6 or IPv4. That said, you can 'hack' around this expected beha

Re: Suspecious DNS traffic

2013-03-25 Thread Carlos M. Martinez
Are you talking about SOURCE or destination ports ? regards ~CArlos On 3/25/13 1:21 PM, babu dheen wrote: > Hi Matus, > > Still not convinced because if i need to allow >1024 port from our DNS > server to external world(internet).. where is the security? > > I beleive we just need to allow TC

Auto-dnssec maintain and 'continous' resigning

2013-04-01 Thread Carlos M. Martinez
Hello all, I have a few zones signed with DNSSEC and "autodnssec maintain". I have one particular zone that every now and then (I'm working on finding a pattern or trigger) This re-signing process runs for a while, incrementing the serial each time and growing the journal until stopping. I know

Re: Auto-dnssec maintain and 'continous' resigning

2013-04-01 Thread Carlos M. Martinez
Reframing the question in more general terms... Which events trigger a zone re-sign and reload when using "auto-dnssec maintain" ? regards, ~Carlos On 4/1/13 12:04 PM, Carlos M. Martinez wrote: > Hello all, > > I have a few zones signed with DNSSEC and "autodnssec

Re: Auto-dnssec maintain and 'continous' resigning

2013-04-04 Thread Carlos M. Martinez
the other options. Looking forward to your thoughts. ~Carlos On 4/3/13 7:48 PM, Mark Andrews wrote: > > In message <515a92a5.3020...@imperial.ac.uk>, Phil Mayers writes: >> On 04/01/2013 07:36 PM, Carlos M. Martinez wrote: >>> Reframing the question in more general ter

Re: signature expiration

2013-04-15 Thread Carlos M. Martinez
If nothing changes, only the SOA serial will be incremented on resign. The signatures don't 'have' to be renewed every 30 days, you can resign as often as you want / need. regards ~Carlos On 4/11/13 9:14 AM, hugo hugoo wrote: > Hello, > > Can anyone tell me why signatures in dnssec mut be ren

Re: ISC Courses

2013-04-26 Thread Carlos M. Martinez
That's stiff... On 4/26/13 2:47 PM, rohan.he...@cwjamaica.com wrote: > Hello, > > Can anyone say why Bind course offering appears so expensive? Is something > else included in the package that is not specified? > > 2-Day Introduction to DNS & BIND Training > Price: $1,795.00 > > Rohan > __

Re: Views Question

2013-04-30 Thread Carlos M. Martinez
I think views have mostly to do with the source of the queries, thus presenting a different 'view' of zone data depending on who the client is. You could have one view only with master zones and other view with salve zones, but I'm not sure what the purpose would be, unless for example you want to

Re: Mailing list "reply-to" setting

2013-05-08 Thread Carlos M. martinez
And, If I might add, adding a tag to the subject like [bind-users] would be extremely nice. regards ~Carlos On 5/8/13 12:02 PM, Steven Carr wrote: > Any chance someone can correct the settings on this mailing list to > reply to the list by default instead of the user posting the message? > > Th

Re: Mailing list "reply-to" setting

2013-05-08 Thread Carlos M. martinez
Agreed, but, subject tagging is very useful for those who prefer to have things hit your inbox first, before archiving. And there seems to be a lot more agreement on the tagging issue than on the reply to. Out of dozens of MLs I'm subscribed to, this is the only one which does not tag the subject,

Re: Mailing list "reply-to" setting

2013-05-09 Thread Carlos M. martinez
On 5/8/13 10:53 PM, Michael McNally wrote: > On 5/8/13 9:43 AM, Carlos M. martinez wrote: >> Agreed, but, subject tagging is very useful for those who prefer to have >> things hit your inbox first, before archiving. And there seems to be a >> lot more agreement on the taggin

Re: Negative zones; NXDOMAIN responses

2013-05-20 Thread Carlos M. Martinez
You need the soa record. It has to be empty but not THAT empty :-) Sent from my iPad On 20 May 2013, at 04:51, Narcis Garcia wrote: > - Yes, I thought about not using DNS from the same internet provider, > but wanted to know if there is a way to patch only the .local response. > > - This is th

Re: Confused about a basic concept

2013-06-05 Thread Carlos M. Martinez
The 'hidden master' setup is a very good strategy for a number of reasons. I think the original description only derails a bit when using the term 'authoritative': > I'm being told "our authoritative DNS >> servers should not receive any queries", as well as "DNS slaves >> respond to quer

Re: This list's prefix

2013-06-05 Thread Carlos M. Martinez
That's a neat trick, thanks Warren! I also do like prefixes, BTW (as can be seen in the other thread referenced). cheers! ~Carlos On 6/5/13 2:46 PM, Warren Kumari wrote: > > On Jun 5, 2013, at 11:43 AM, Narcis Garcia wrote: > >> It's not the only mailing list where I'm subscribed. >> Could p

Re: Rate-Limit Question

2013-06-14 Thread Carlos M. Martinez
You need to patch your 9.9.2 source code and recompile. Take a look at: http://www.redbarn.org/dns/ratelimits cheers, ~Carlos On 6/14/13 11:27 AM, Manson, John wrote: > We are running Bind 9.9.2 and would like to invoke the rate-limit option > but named says ‘unknown option’. > > Do we need to

Re: Rate-Limit Question

2013-06-14 Thread Carlos M. Martinez
Evan, thanks for the heads up. Do you have a estimated time of release for 9.9.4 and 9.9.10 ? Warm regards, ~Carlos On 6/14/13 1:08 PM, Evan Hunt wrote: > On Fri, Jun 14, 2013 at 03:36:19PM +0100, Phil Mayers wrote: >> It's not built into bind (yet). > > Correct. For the record, it'll be in

Re: Rate-Limit Question

2013-06-14 Thread Carlos M. Martinez
tks !! On 6/14/13 1:21 PM, Evan Hunt wrote: > On Fri, Jun 14, 2013 at 01:10:47PM -0300, Carlos M. Martinez wrote: >> thanks for the heads up. Do you have a estimated time of release for >> 9.9.4 and 9.9.10 ? > Every time I make predictions about dates, events conspire to make &