Re: A record of domain name must be name server ?

2014-09-08 Thread Matus UHLAR - fantomas
server IP address ? yes. ... it's completely irelevant where does example.com A record point to. It could only issue a problem if you pointed "example.com. NS example.com." or similar MX etc recods. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning:

Re: A record of domain name must be name server ?

2014-09-10 Thread Matus UHLAR - fantomas
crap associated with the WWW address. Keeping track of one extra A record (and associated record if you go in that direction) isn't a bad thing. simply said: don't CNAME to @. (Personal preferences, of course) yes, but still... -- Matus UHLAR - fantomas, uh...@fantomas

Re: A record of domain name must be name server ?

2014-09-11 Thread Matus UHLAR - fantomas
m. The same applies for all other RRs for exmaple.com Alan named crap. And that's why I also think it's better to define 'www' as A record, not as CNAME -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to

Re: A record of domain name must be name server ?

2014-09-11 Thread Matus UHLAR - fantomas
On 9/11/2014 3:47 AM, Matus UHLAR - fantomas wrote: On 10.09.14 18:13, Kevin Darcy wrote: No, what I'm saying is that if example.com owns an A record 203.0.113.48, and www.example.com owns an A record 203.0.113.48, then where does 48.113.0.203.in-addr.arpa point? Completely your dec

Re: A record of domain name must be name server ?

2014-09-11 Thread Matus UHLAR - fantomas
On 9/11/2014 12:08 PM, Matus UHLAR - fantomas wrote: we both also said it's personal preference. On 11.09.14 12:53, Kevin Darcy wrote: And I'm saying that's a cop-out. It should be a recommended practice encouraging consistent forward/reverse mappings is something that all

Re: A record of domain name must be name server ?

2014-09-12 Thread Matus UHLAR - fantomas
t redirecting only for A and/or , nor any particular types, only everything (CNAME). Is there already and RFC for this? I'm not sure whether this kind of RR should be introduced. Maybe redirect that defines types to be redirected... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.

Re: How does bind 9.x chooses root servers?

2014-09-19 Thread Matus UHLAR - fantomas
On 19.09.14 15:57, Jittinan Suwanruengsri wrote: How does bind 9.x chooses root servers? based on RTT, with ocasional re-tries of other servers try googling for "bind server selection" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: Diagnostic help

2014-09-30 Thread Matus UHLAR - fantomas
got that right, or how to correct it if I don't. correct. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Due to unexpected conditio

Re: forwarding zone to another DNS server problem

2014-11-03 Thread Matus UHLAR - fantomas
tic-stub" to forward to an authoritative server. the same applies here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. LSD will mak

Re: forwarding zone to another DNS server problem

2014-11-03 Thread Matus UHLAR - fantomas
On 02.11.14 23:09, Frank Pikelner wrote: What is the advantage of using a "stub" or "static-stub" to using a slave? you should use them when it's not possible or viable to use slave, e.g. windows AD domain, RBL domain, domain that can't be transferred etc...

Re: How to debug BIND

2014-11-30 Thread Matus UHLAR - fantomas
On 30.11.14 11:24, Kaouthar Chetioui wrote: I have already use +trace it gives me the following answer, like this: no, it doeas not: global options: +cmd you clearly did not use +trace here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: rndc flushname not working

2014-12-10 Thread Matus UHLAR - fantomas
ushing the name work? I'm afraid we can't tell you without precise information. However, the institution should get at least one backup DNS server... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address.

Re: rndc flushname not working

2014-12-11 Thread Matus UHLAR - fantomas
ushing the name work? On Wed, Dec 10, 2014 at 3:36 AM, Matus UHLAR - fantomas wrote: I'm afraid we can't tell you without precise information. However, the institution should get at least one backup DNS server... On 11.12.14 09:35, Bob Harold wrote: If a DNS server does not res

Re: Question about how forwarders work

2014-12-11 Thread Matus UHLAR - fantomas
using forwarders. Especially for mail servers with anti-spam measures, where your forwarders may be ignored by some blacklists, because they send too much queries. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Question about how forwarders work

2014-12-16 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas Sent: 11 December 2014 16:39 To: bind-users@lists.isc.org Subject: Re: Question about how forwarders work On 11.12.14 16:28, Richard Thomas wrote: Please could I have some advice about how the below example configuration would work: forwarders { A.B.C.D; E.F.G.H; }; What I w

Re: can't-resolve

2014-12-25 Thread Matus UHLAR - fantomas
e SERVFAIL message should be explained in the logs... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: can't-resolve

2014-12-26 Thread Matus UHLAR - fantomas
ng up makksab.com, it directs us to: makksab.com.172800 IN NS ns2.cyberia.net.sa. ns2.cyberia.net.sa. 600 IN A 212.119.64.3 is this any of your nameservers? when I query your IPS above, 212.119.64.12 does not answer, the others do. -- Matus UHLAR -

Re: can't-resolve

2014-12-26 Thread Matus UHLAR - fantomas
you sure there is no firewall, or "security" gateway between your server and the world? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu po

Re: BIND9 Return different IP address based on subnet

2014-12-29 Thread Matus UHLAR - fantomas
need views when you have different versions of the same zone. in your example you could use single view with all of the zones. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: BIND9 Return different IP address based on subnet

2015-01-03 Thread Matus UHLAR - fantomas
On 03.01.15 19:24, Christian Kette wrote: I have found a workaround. I defined a different zone for every network I repeat: you don't need views when having different zones. You would need views if you had the same zone with different content. -- Matus UHLAR - fantomas, uh...@fantom

Re: can't-resolve

2015-01-04 Thread Matus UHLAR - fantomas
tus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about cholesterol. ___ Ple

Re: bind-users Digest, Vol 2011, Issue 1

2015-01-04 Thread Matus UHLAR - fantomas
only the differing zone(s), and one view to contain all other zones. Other views would use the default view as forwarder (and share the cache for effectivity) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: reject invalid dns queries

2015-01-19 Thread Matus UHLAR - fantomas
allow recursion for remote clients? (recursion and allow-recursion statemends) Do you allow DNS access from remote clients? (allow-query statement) Perhaps denying remote clients from even accessing your caching server would help you with this problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: reject invalid dns queries

2015-01-20 Thread Matus UHLAR - fantomas
s) Do you allow DNS access from remote clients? (allow-query statement) Perhaps denying remote clients from even accessing your caching server would help you with this problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertisi

Re: Allowing recursive queries of 'static-stub' zones

2015-01-29 Thread Matus UHLAR - fantomas
ont or just for your clients? In the latter case the allow-recursion should help you for both cases, you don't need to specify allow-query. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varova

Re: bad zone not loaded

2015-02-03 Thread Matus UHLAR - fantomas
CKING" = yes in order that BIND starts. "check_names master ignore;" will make BIND ignore loading errors. Note that it's much better to fix provisioning... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising t

Re: have a question of using bind9 for local proxy server

2015-03-02 Thread Matus UHLAR - fantomas
y to malicious server and the others would get bad DNS data. ...while DNSSEC would avoid this issue, it would then be simply useless to do this. My recommendation: don't redirect DNS traffic. Either allow it or block it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warni

Re: Too many connections on the same IP

2015-03-03 Thread Matus UHLAR - fantomas
tests, i noticed that if from clients i used an ip alias of Bind server, it worked perfectly! Only on main ip there were congestion problems, but resolving on ip aliases worked fastly! do you have any firewall in front of your DNS server? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: ideas for cloud server

2015-03-18 Thread Matus UHLAR - fantomas
On 18.03.15 14:18, Heamnath J wrote: How to change centos server as real time cloud server ?.. please be more specific. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread Matus UHLAR - fantomas
I'm right, the only question is how to simplify the configuration so not to have two definitions in two files for every slave zone which is shared between views. maybe you could put all those zone definitions into one file and include it in each view. the only other way is stop using views..

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread Matus UHLAR - fantomas
On 18.03.15 11:48, Constantin Stefanov wrote: then both views will refernce ther same writable file, won't they? Or am I missing something about "in-view" directive? On 18.03.2015 11:56, Matus UHLAR - fantomas wrote: maybe you could put all those zone definitions into one file

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread Matus UHLAR - fantomas
On 18.03.2015 13:02, Matus UHLAR - fantomas wrote: On 18.03.15 11:48, Constantin Stefanov wrote: then both views will refernce ther same writable file, won't they? Or am I missing something about "in-view" directive? On 18.03.2015 11:56, Matus UHLAR - fantomas wrote: maybe yo

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread Matus UHLAR - fantomas
t and prevention from using the same file multiple times (I remember discussion about issues coming from those here on the list). you are complaining about your broken configuration worked. Sorry, I gave up arguing with you. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantom

Re: BIND not loading into memory on first transfer

2015-03-26 Thread Matus UHLAR - fantomas
s the question really is, is this expected behavior or a bug? What's the SOA? It's possible that the zones were not expired, so they were provided as saved on disk. Since BIND wasn't able to transfer newer versions, it continued providing old versions. -- Matus UHLAR - fantomas, uh..

Re: BIND not loading into memory on first transfer

2015-03-26 Thread Matus UHLAR - fantomas
On Thu, Mar 26, 2015 at 12:17 PM, Matus UHLAR - fantomas wrote: What's the SOA? It's possible that the zones were not expired, so they were provided as saved on disk. Since BIND wasn't able to transfer newer versions, it continued providing old versions. On 26.03.15 12:48, F

Re: BIND not loading into memory on first transfer

2015-03-27 Thread Matus UHLAR - fantomas
transfer, permission denied writing the tmp-x file that happens prior to writing it out to the zone file itself. and how do hey differ from the second transfer? If they don't itmay be a bug (or a "bug") in named that it behaves differently after first and other transfer

Re: NAMED try to solve domain from old authoritative server

2015-04-02 Thread Matus UHLAR - fantomas
cache, the problem occur again. Does anyone ever face this problem? such problems appear when people put incorrect NS records to zone files. Note that not only parent zone must have proper NS (glue) records to child zones, but the child zones must have them too. -- Matus UHLAR - fantoma

Re: bind-users Digest, Vol 2083, Issue 1

2015-04-07 Thread Matus UHLAR - fantomas
cursive warning - which I obviously dont want. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.

Re: rndc flushname not working

2015-04-09 Thread Matus UHLAR - fantomas
ed to, still had to flush the entire cache to get resolution working properly on that domain again. this indicates that any of NS records the domain points to returns NXDOMAIN for the domain. hard to tell without more info, but some web DNS checkers are able to trace this kind of issues... -- M

Re: Suppress log entry...

2015-04-14 Thread Matus UHLAR - fantomas
in other words: if you everytime you change the config hard restart > named instead a reload you are doing it terrible wrong with a ton of bad > side effects -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to thi

Re: Getting an error on a simple DNS configuration

2015-06-03 Thread Matus UHLAR - fantomas
rn using host and/or dig -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Emacs is a complicated operating system with

Re: Automatic . NS queries from BIND

2015-06-17 Thread Matus UHLAR - fantomas
the hard-coded hints file changes whenever new BIND release gets out, while the bungled hints file may be updated by packagers or manually. I'd say that the bundled hints file is likely to be newer than the hard-coded one. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.s

Re: file descriptor exceeds limit

2015-06-18 Thread Matus UHLAR - fantomas
lt to increased number of TCP queries which slows down resolution ... By the way, the resolvers are running RHEL 6.x. precise BIND version would help a bit more... seems RH6.6 contains 9.8.2 but that may be different for older RH6 versions. -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: file descriptor exceeds limit

2015-06-19 Thread Matus UHLAR - fantomas
ike Hoskins (michoski) wrote: Just following along, for the record... On our side, iptables is completely disabled. We do that sort of thing upstream on dedicated firewalls. Just now getting time to reply to Cathy...more detail on that there. aren't those firewalls overloaded? -- Matus UH

Re: setting and monitoring dns cache master / slave pair

2015-07-07 Thread Matus UHLAR - fantomas
On 06.07.15 16:39, Leandro wrote: 3)Does it have any drawbacks no declaring any zone file in the long term? you should declare at least RFC 1918/3330/5735 reverse zones, to prevent from forwarding queries to root servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: How to properly update chroot-bind

2015-07-28 Thread Matus UHLAR - fantomas
~]# uname -a Linux centos-dns1.virtual.com.ar 2.6.32-504.23.4.el6.x86_64 #1 SMP Tue Jun 9 20:57:37 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux Doing yum update bind-chroot is not the way. This is not a production server yet but it will be soon. yum update bind should do that. -- Matus UHLAR - fantomas

Re: How to properly update chroot-bind

2015-07-28 Thread Matus UHLAR - fantomas
~]# uname -a Linux centos-dns1.virtual.com.ar 2.6.32-504.23.4.el6.x86_64 #1 SMP Tue Jun 9 20:57:37 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux Doing yum update bind-chroot is not the way. This is not a production server yet but it will be soon. Am 28.07.2015 um 09:10 schrieb Matus UHLAR - fantomas

Re: How to properly update chroot-bind

2015-07-28 Thread Matus UHLAR - fantomas
Am 28.07.2015 um 10:56 schrieb Matus UHLAR - fantomas: but you *never ever* should only update specific packages on a RHEL/CentOS system because that is *not supported and tested* at all No? What are dependencies for, then? Or don't yum/RPM support them in the way debian does? (that i

Re: DNS format error

2015-07-28 Thread Matus UHLAR - fantomas
apparently won't get this error... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Enter any 12-digit prime number to con

Re: bind 9.8 named_stats parser

2015-08-05 Thread Matus UHLAR - fantomas
just dnsstats.pl -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #98652: Operation completed success

Re: [OT] Re: configuration error in lists.isc.org

2015-08-06 Thread Matus UHLAR - fantomas
the braindead SenderID specification that broke this behaviour. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "One World. One Web. One Progr

Re: [OT] Re: configuration error in lists.isc.org

2015-08-07 Thread Matus UHLAR - fantomas
Am 07.08.2015 um 08:29 schrieb Matus UHLAR - fantomas: SPF must only check envelope address, not header From: address - it was never designed to do the latter. On 07.08.15 17:23, Heiko Richter wrote: Correction: - All implementations of SPF always check 2 addresses: - Envelope

Re: DNS Negative Caching

2015-08-28 Thread Matus UHLAR - fantomas
s. Note that is only matters on masters, the XFER slaves see the ttl within each record... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu post

Re: Solved - Re: A tale of two nameservers - resolution problems

2015-09-03 Thread Matus UHLAR - fantomas
lthough it doesn't fix the issue with boards without RTC. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. We are but packets in the I

Re: questions about DNS notify

2015-09-10 Thread Matus UHLAR - fantomas
master query from, to get the IP addresses for those slaves? it will run standard resolution procedure - try lookup from root, or configured forwarders, unless having nsbeta.info configured locally. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: Multiple A and PTR and the "main" ones?

2015-09-11 Thread Matus UHLAR - fantomas
t be useful. Is it a bad practice? it is a bad practice and leads exactly to the problems you describe when the other side tries to verify A/PTR matching because there is just no ordering like there is also no rodering having multiple A records for the same name with different IP's agree

Re: Options for non-recursive servers

2015-09-23 Thread Matus UHLAR - fantomas
you can in some cases receive multiple requests that could be avoided without this. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They tha

Re: FW: SRV Request to DNS

2015-10-12 Thread Matus UHLAR - fantomas
care themselves. please provide more detailesd question, or search archives if it hasn't been answered already. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOS

Re: dname reverse delegation

2015-10-14 Thread Matus UHLAR - fantomas
ave yourself trouble by doing so? If not, you should probably reconsider. [...] Don't be distracted by RFC2317. It describes the trickery you need when you're dealing with a longer prefix (fewer addresses) than a /24. If you have "a few /24", you can deal with them withou

Re: How does a Client Verify if the DNS server is Alive or down

2015-10-19 Thread Matus UHLAR - fantomas
es it periodically send any messages to the server. What Kind of messages are required by the client to be sent towards server to determine if the DNS IP is reachable or not? what is your problem? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: Why two lookups for a CNAME?

2015-10-22 Thread Matus UHLAR - fantomas
ar.example too... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Depression is merely anger with

Re: Why two lookups for a CNAME?

2015-10-23 Thread Matus UHLAR - fantomas
Am 22.10.2015 um 14:01 schrieb Matus UHLAR - fantomas: I wonder if it's not enough to verify that the first response was received from proper server. Since play.l.google.com is a subdomain of play.google.com, the lookup would go throuth google.com nameservers again... when server

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks,  I'd choose logging at kernel level in iptables firewall. ULOG and ulogd can log to libpcap format. -- Matus

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks, Am 27.12.2015 um 18:07 schrieb Matus UHLAR - fantomas: I'd choose logging at kernel level in iptables firewall.

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks, Am 27.12.2015 um 18:07 schrieb Matus UHLAR - fantomas: I'd choose logging at kernel level in iptables firewall.

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
Hello, On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks,  On 27.12.15 18:07, Matus UHLAR - fantomas wrote: I'd choose logging at kernel level in iptables firewall.

Re: Allow-Query=any

2016-01-07 Thread Matus UHLAR - fantomas
so, instead of providing type "ANY" you want people to flood your server with multiple queries for type? if you have problems, response rate limiting should be better solution. ...I received spam from comnpany with NS hosted at cloudflare that refuses ANY query. I am considering ignoring such

Re: has no address records (A or AAAA)

2016-01-28 Thread Matus UHLAR - fantomas
uot;cts.org" in file "192.168.99.zone" that contains the reverse zone, not zone cts.org. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukol

Re: Intermittent NXDOMAIN for a name we are forwarding

2016-02-20 Thread Matus UHLAR - fantomas
"Unassociated entries" when the problem happens. anything more isble in the cache? last time I have encountered this error, it was problematic Cisco DNS load balancer, responding NXDOMAIN to a PTR (and possibly other) type queries, while standard types returned proper answer. -- M

Re: Intermittent NXDOMAIN for a name we are forwarding

2016-02-22 Thread Matus UHLAR - fantomas
now.. doesn't the log also contain info where did that message come from? Our current work around is to restart named (which cache) or we could do a 'rndc flush'. "rndc flushname myname.mydomain.com" should be enough - not needed to flush whole cache. -- M

Re: what does "max-ncache-ttl 0;" mean?

2016-03-02 Thread Matus UHLAR - fantomas
effect it would disable negative cacheing. which means, DON'T DO THAT. anyone searching for nonexisting DNS names (e.g. because of a misconfiguration) could easily DoS your server. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Multiple A records and reverse DNS

2016-03-19 Thread Matus UHLAR - fantomas
yahoo, aol, without any valid reason. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The early bird may get the worm, but the second mous

Re: about NS server authorize

2016-03-21 Thread Matus UHLAR - fantomas
el, saying nameserver not authorized. contact your registrar about this issue. thisa is not a bind problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolve

Re: multi zone forward ?

2016-04-02 Thread Matus UHLAR - fantomas
e view where clients belong and forward everything... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. LSD will make your ECS screen display

Re: i have a question ?

2016-04-14 Thread Matus UHLAR - fantomas
cursion no ), i found forwarding required recursion. You must turn recursion on (and allos it for your IPs) to do the forwarding. Note that in most cases it's useless to do forwarding if your bind server has connectivity and can do the lookups itself. -- Matus UHLAR - fantomas, uh..

Re: Logging question about message 'update-security: error: client update denied'

2016-05-17 Thread Matus UHLAR - fantomas
ey "xcat_key"; }; notify yes; also-notify {10.20.0.100; 10.20.0.101;}; }; apparently the client who asks for update does not know the "xcat_key". ...many windows machines tend to register their name in DNS (it's on by default in netowr

Re: resolution problem

2016-05-19 Thread Matus UHLAR - fantomas
.121#53(dns1.colostate.edu) in 36 ms often a problem of invalid NS delegation, or bad TTL (A record for a server expires before NS record). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: resolution problem

2016-05-19 Thread Matus UHLAR - fantomas
a.colostate.edu. >dpc.cira.colostate.edu. 3600IN A 129.82.109.62 >;; Received 83 bytes from 129.82.103.121#53(dns1.colostate.edu) in 36 ms In article , Matus UHLAR - fantomas wrote: often a problem of invalid NS delegation, or bad TTL (A record for a server expires before NS record)

Re: Forward zone not working

2016-05-21 Thread Matus UHLAR - fantomas
ea how will ordinary DNS in ipv6 look like, but I doubt it will look like this... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Despite the

Re: Forward zone not working

2016-05-21 Thread Matus UHLAR - fantomas
S protocol just to provide generic DNS records for each leaf (home) network... yes, we need something new for IPv6. But not for creating bulks of useless generic records. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: resolution problem

2016-05-24 Thread Matus UHLAR - fantomas
In article , Matus UHLAR - fantomas wrote: often a problem of invalid NS delegation, or bad TTL (A record for a server expires before NS record). On 19.05.16 15:31, Sam Wilson wrote: Glue A records for the nameservers have 172800 TTL, authoritative A records have 1200. that'

Re: Strange intermittent resolution

2016-05-27 Thread Matus UHLAR - fantomas
.com. amlinuxmedia.com. 86400 IN NS ns2.host-for.com. got it? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One OS to rule

Re: Ability to limit memory usage for zones on an authoritative server.

2016-06-05 Thread Matus UHLAR - fantomas
ot an issue) and didn't want to do the work of changing some standard zone lists and data we use. what kind of zones are they? why do you load them if you don't want to use them? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adve

Re: Append a Hard-coded Text Tuple into Additional Section of "dig" Feature

2016-06-17 Thread Matus UHLAR - fantomas
ome information that I want to include" 1. there's no point in adding TXT rrs to additional section, they do not belong there 2. why at all do you want to put them there? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail ad

Re: Unable to understand why a different A record response being sent by bind

2016-06-20 Thread Matus UHLAR - fantomas
instead of test1.com for examples... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast t

Re: Resolving issue on specific domain

2016-07-15 Thread Matus UHLAR - fantomas
means, 194.126.10.18 does not know the "domainname" you must add localhost to resolv.conf as first nameserver to get answers from it by default. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Var

Re: Sending extra info in bind dns query packet

2016-07-15 Thread Matus UHLAR - fantomas
packet? Is there other way I can send this extra info through the bind dns query packet? it's highly dependent on what exactly you want to achieve. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. V

Re: Resolving issue on specific domain

2016-07-15 Thread Matus UHLAR - fantomas
On 15.07.16 12:05, Daniel Dawalibi wrote: To: 'Matus UHLAR - fantomas' , bind-users@lists.isc.org please avoid personal replies. use list-reply whenever possible. I already did it as per below output of resolv.conf but problem persists. do you want to say, even if you run "

Re: Resolving issue on specific domain

2016-07-15 Thread Matus UHLAR - fantomas
ed Dig domainame localhost -> Resolving properly and, please remove the parts that are not important, don't sent useless crap to mailing list. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varo

Re: Resolving issue on specific domain

2016-07-16 Thread Matus UHLAR - fantomas
On 15.07.16 14:05, Daniel Dawalibi wrote: Dig domainname -> Server failed On Jul 15, 2016, at 8:48 AM, Matus UHLAR - fantomas wrote: please show us output of it. when 127.0.0.1 is first in /etc/resolv.conf, dig should contact localhost first, and the result should be the same as

Re: Query on the Order in which RR are answered by Bind of Order/preference are Same

2016-07-18 Thread Matus UHLAR - fantomas
for your bind instance - any other nameserver can change the order. why don't you use higher order if you want to have them in order? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tut

Re: Questions on how to setup Reverse DNS in bind 9

2016-07-19 Thread Matus UHLAR - fantomas
05 now... Because I didn't setup another A name for franklin? Thanks and sorry for all the questions. I know these probably aren't really bind related questions anymore. Thanks! once more: jetbbs.com IS NOT franklin.jetbbs.com ! FYI currently they both only contain 104.238.117.105

Re: Questions on how to setup Reverse DNS in bind 9

2016-07-20 Thread Matus UHLAR - fantomas
gain but when we get into the new house, I'll change it so the IP address for the second A record points to my server at the house. That way, if one server goes down, people can still connect. It'd be a great opportunity to learn this stuff a bit more I think. good idea. -- Matus UHLAR

Re: Questions on how to setup Reverse DNS in bind 9

2016-07-20 Thread Matus UHLAR - fantomas
ally edited the httpd.conf file and regenerated the SSL certs, things might have started working. this is your problem. don't generate ssl keys when adding IPs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this

Re: Overriding TTL per resource-record on slave

2016-07-25 Thread Matus UHLAR - fantomas
My Idea is to run a dynamic update (nsupdate) wrapper script to update TTL entries for desired resource-records on our slave. Is there a better way to achieve this? your slave will only forward the update to master. Your description does not make sense, what exactly do you want to achieve?

Re: Overriding TTL per resource-record on slave

2016-07-26 Thread Matus UHLAR - fantomas
DNS master? since all resource records have their own TTL, you can simply give those you want lover TTL than the others. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: outgoing-traffic

2016-07-27 Thread Matus UHLAR - fantomas
or it and the traffic has already hit your system before ANY queries would be denied. however, if no responses will come from his server, it's more likely that the queries will stop. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail a

Re: outgoing-traffic

2016-07-27 Thread Matus UHLAR - fantomas
On 27 July 2016 at 15:10, Matus UHLAR - fantomas wrote: however, if no responses will come from his server, it's more likely that the queries will stop. On 27.07.16 15:19, S Carr wrote: If you look at the capture there doesn't appear to be any responses being sent for the ANY

Re: getting not authoritative with some notifies - Solved

2016-07-29 Thread Matus UHLAR - fantomas
complain and tell them they should tell you when tthey migrated their zones off. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R)etry, (A

Re: getting not authoritative with some notifies - Solved

2016-07-30 Thread Matus UHLAR - fantomas
On 2016-07-29 08:21, Matus UHLAR - fantomas wrote: On 28.07.16 12:13, Paul A wrote: Now what is everyone using to make sure the zones in named.conf are still pointing to your NS servers? I have a lot of stale DNS zones I want to remove. separate authoritative and recursive servers. bill for

<    2   3   4   5   6   7   8   9   10   11   >