Re: Increase in retry and timeout errors post 9.9.4 -> 9.11.4 upgrade

2020-05-03 Thread Gareth Parks
users@lists.isc.org Subject: Re: Increase in retry and timeout errors post 9.9.4 -> 9.11.4 upgrade Message from External Sender Well BIND 9.11+ supports DNS COOKIE by default and there are some servers that mishandle EDNS requests with a DNS COOKIE option present. Unknown EDNS options are suppos

Re: Increase in retry and timeout errors post 9.9.4 -> 9.11.4 upgrade

2020-05-03 Thread Mark Andrews
Well BIND 9.11+ supports DNS COOKIE by default and there are some servers that mishandle EDNS requests with a DNS COOKIE option present. Unknown EDNS options are supposed to be ignored, but there are servers/firewalls that just drop such queries. Others return FORMERR, others return NXDOMAIN w

Increase in retry and timeout errors post 9.9.4 -> 9.11.4 upgrade

2020-05-03 Thread Gareth Parks
Hi, I have three centos 7 servers running bind acting as internal resolvers. There was an update released that upgrades them from 0:9.9.4-74.el7_6.2 to 32:9.11.4-16.P2.el7_8.2. On performing this upgrade to one of the servers there has been a notable increase in retry and timeout errors as meas