Re: Load balancer for Bind

2016-09-16 Thread bert hubert
On Fri, Sep 16, 2016 at 02:22:24PM +0100, Phil Mayers wrote: > I was mainly wondering about the comment: > > """ > dnsdist is still very fresh software. However, we are actively seeking Hi Phil, Thanks - that statement was accurate in March 2015 when we posted that item. I have now replaced it

Re: Load balancer for Bind

2016-09-16 Thread bert hubert
On Fri, Sep 16, 2016 at 02:03:31PM +0100, Phil Mayers wrote: > >Sorry for running advertisement here. But please know dnsdist is software > >neutral, it is not "powerdnsdist". > > I've never come across dnsdist before. Would you describe it as > production-ready? Hi Phil, A large CDN, one of

Re: Load balancer for Bind

2016-09-15 Thread bert hubert
On Wed, Sep 14, 2016 at 03:41:31PM -0400, Matthew Pounsett wrote: > > I read something about HAProxy but it does not manage udp connection and > > the interesting security proxy/balancer DnsDist does not pass original > > client ip for Bind-DLZ... > > > Your best option is something that can do

Re: Load balancer for Bind

2016-09-14 Thread bert hubert
On Wed, Sep 14, 2016 at 06:17:13PM +0200, Job wrote: > which is the best load balancer for two or more Bind DNS Server, located in > the same farm? > I read something about HAProxy but it does not manage udp connection and the > interesting security proxy/balancer DnsDist does not pass original

Re: ISC considering a change to the BIND open source license

2016-06-14 Thread bert hubert
On Mon, Jun 13, 2016 at 08:57:02PM +, P Vixie wrote: > This is long overdue. I'm all for it. Vixie For what it is worth, as open source fellow travellers we discussed this earlier both with Vicky and Paul, and we are in strong agreement with this measure to increase the sustainability of

Re: New type of DDoS? Anyone saw it?

2016-05-16 Thread bert hubert
On Mon, May 16, 2016 at 09:20:17PM +0200, Marek Królikowski wrote: > Hello > I just call to one of the client who do this DDoS and he confirm, he use UBI > devices > Anyone know how to block all query like this: "query 331.206.372.214 IN > " with random AAA.XXX.YYY.ZZZ address?

Re: New type of DDoS? Anyone saw it?

2016-05-16 Thread bert hubert
On Mon, May 16, 2016 at 05:03:01PM +0200, Marek Królikowski wrote: > Today i saw my bind eat almost 90% of RAM when i check logs I find > interesting DDoS on my DNS Cluster today: > 16-May-2016 16:47:47.467 client 8X.1X0.3Y.40#44968: query: 323.016.231.212 > IN + (8X.1X0.Y.Y) This may be

Re: BIND 9.11 / edns-client-subnet

2016-05-09 Thread bert hubert
On Mon, May 09, 2016 at 05:24:50PM +0200, Nico CARTRON wrote: > > Perhaps you should tell us how it works for you, what your testing has  > > found, and contribute to the development of great open source software?  > well, I am just starting the tests now, so cannot tell - yet :) > I will

Re: BIND 9.11 / edns-client-subnet

2016-05-09 Thread bert hubert
On Mon, May 09, 2016 at 04:38:13PM +0200, Nico CARTRON wrote: > I was wondering whether some folks on the mailing list had a look at the ECS > implementation in BIND 9.11, > and if they had any feedback to share? Perhaps you should tell us how it works for you, what your testing has found, and

Re: pre heat cache

2016-02-17 Thread bert hubert
On Wed, Feb 17, 2016 at 11:31:54AM -0800, William Taylor wrote: > Is there anyway to pre-heat the cache in bind on startup besides having > a custom script that did a bunch of queries on top hosts? > I know you can dump it with rndc but can you load it back ? One way to achieve this is to have