ponses, then named can 'get stuck' on using
>and re-using the same refresh source port.
>...
Thank you, that was exactly the cause, and the fix.
Some years ago I'd updated a host-based firewall running on my BIND slave
server
to block traffic to an additional inbound UDP po
What can happen (and this is really really subtle) is that if there are
some source ports that named could randomly select, but where
intermediate firewalls or filters are just dropping, either the SOA
refresh queries, or the responses, then named can 'get stuck' on using
and re-using the same refr
Apologies in advance for this lengthy description.
Since making I made a configuration change a few weeks ago, every 1-3 days, my
BIND 9.9.7 server experiences several hours of retry/timeout failures while
performing UDP-based SOA serial number queries (zone refresh).
My server acts like it doesn
Last admin didn't have correct master ip set, put the correct on and all good.
On Tue, Jul 24, 2012 at 2:30 PM, Gregory Machin wrote:
> Hi.
> I have a bind 9 primary server and a bind 9 secondary server, I added
> a new sub domain to the primary and as a slave zone on the secondary.
> i have obvi
In article ,
Gregory Machin wrote:
> Hi.
> I have a bind 9 primary server and a bind 9 secondary server, I added
> a new sub domain to the primary and as a slave zone on the secondary.
> i have obviously missed something. What does :
>
> named[13931]: zone domain.example.com/IN: refresh: unexpe
Hi.
I have a bind 9 primary server and a bind 9 secondary server, I added
a new sub domain to the primary and as a slave zone on the secondary.
i have obviously missed something. What does :
named[13931]: zone domain.example.com/IN: refresh: unexpected rcode
(NXDOMAIN) from master 209.234.97.14#53
Running off SSDs has also proved to help startup/reload times in our usage.
Dan Durrer
No-IP
On Mar 2, 2011, at 5:32 AM, david klein wrote:
> One other thing: on the filesystem in which reside directories that
> house the zone files, set the mount option "noatime". This will
> improve the perf
One other thing: on the filesystem in which reside directories that
house the zone files, set the mount option "noatime". This will
improve the performance of re-reading the zone files because it will
take out the necessity of updating a time-stamp for each read.
-DTK
On Mon, Feb 28, 2011 at 7
On 2/27/2011 1:15 AM, Dennis Perisa wrote:
> Thanks Doug. Yes, helps a lot. And yes, this is to handle adding new
> zones.
Look into BIND 9.7.2 or newer and the "rndc addzone" capabilities.
Solves the problem without needing to reload/restart/reconifg at all.
AlanC
signature.asc
Description
5 files in a single directory will make difficult for any
filesystem. I would recommend breaking that out into groups of less
than 1 per directory. For better performance, separate them onto
directories that are on different spindles; the parallelization of
seek (and with thousands of small
Thanks Doug. Yes, helps a lot. And yes, this is to handle adding new
zones.
Glad I'm on the right track :) I should point out that those ideas came
from trawling this and many other forums!
I should also point out that when I said "short-term fix", I meant these
were changes we could implement
On 02/26/2011 18:56, Dennis Perisa wrote:
Hi folks,
I'm looking for suggestions to substantially improve reload times on a
slave that is serving 50,000 zones (mostly customer zones).
'rndc reload' is being executed on the slave every 15 minutes.
Yeah, don't do that. :) Is this being done to
Hi folks,
I'm looking for suggestions to substantially improve reload times on a slave
that is serving 50,000 zones (mostly customer zones).
'rndc reload' is being executed on the slave every 15 minutes. Due to the
large number of zones to trawl through, the reload process is causing
intermitten
or, alternatively, that some other device steps in to
associate itself with that IP address in the case of failure (which it
would detect through some sort of "heartbeat" or "keepalive" mechanism
between the nodes).
I would also like the slave server to automatically add any
Hi everyone
Very new to bind (or dns for that matter).
I am wanting to know if there is a way to setup a slave only server for my
network.
I would like it to simply act as a secondary server should the main server
fail.
I would also like the slave server to automatically add any (all) new
In message <560485.29733...@web36105.mail.mud.yahoo.com>, Brad Beckenhauer writ
es:
> Running Centos 5.5 with bind-9.3.6-4.P1.el5_4.2 (from the Centos repo) and I'
> m unable to get a slave server to retrieve the zone file from the master.
>
> The master nameserver has a
Running Centos 5.5 with bind-9.3.6-4.P1.el5_4.2 (from the Centos repo) and I'm
unable to get a slave server to retrieve the zone file from the master.
The master nameserver has a public ip address, the slave sits behind a firewall
/ NAT on a private ip address.
When I update a zone file o
type master;
allow-transfer { other.servers.ip.addresses; };
perhaps?
I tend to do
options {
...
allow-transfer {"none";};
...
};
But this wouldn't explain why all the rest can transfer and the one zone
can't.
Have you made sure that the slaved copies for
Many thanks for all the help first up :-) I really do appreciate it!
Am just wondering, I'm running BIND 9.6.0-P1 on Solaris 9 to achieve
this, so could this be a bug or something else yet not implemented into
Bind or perhaps somehow the way it was compiled as I'm using the
Blastwave version..
Acl's are "first match".
What you had devolves to
match-clients { any; };
Try.
match-clients { !192.168.0.0/22; !127.0.0.1; any; };
Adjust all the other acls
Ok so these are similar to Cisco IOS Acl's now I get it :-)
Unfortunately the reverse zone is still not transferr
ne for the external view isn't
> transferring to my slave server this is quite strange as all the
> other forward zones for the external view work fine??
>
> Here is config:
>
>
>
> named.conf file snippit for both servers:
>
> view "external" {
David M. Dowdle wrote:
I suspect your secondary has the IP address of 192.168.1.101 ? your
match statement blocks it, as the FIRST match stops procssing, and the
first match is the !192.168.0.0/22, prohibiting queries. Move the
permit before the deny in this case. (the general case is put more
Hi,
now that I have my zones and reverse files sorted out I have managed to
come across a problem which seems I had before even beginning any of this!
Basically for some reason my reverse zone for the external view isn't
transferring to my slave server this is quite strange as al
In article ,
$B%"%k%Y%k%H(B wrote:
> Just simple question.
>
> I'm setting up slave dns server, my question, is do I need to transfer
> Reverse zone
> too ? or just domain zone is enough?
>
> thank you for any help
You need to transfer any zones that ar
アルベルト wrote:
Just simple question.
I'm setting up slave dns server, my question, is do I need to transfer Reverse
zone
too ? or just domain zone is enough?
Sort of impossible to answer, without more information.
Why did you set up a slave server in the first place? Redun
Just simple question.
I'm setting up slave dns server, my question, is do I need to transfer Reverse
zone
too ? or just domain zone is enough?
thank you for any help
___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/l
> I I create this configuration for my secondary server:
>
> options {
> forward only;
> forwarders { serverA ; } ;
> } ;
>
> zone "example.com"{
> type slave;
> file "zone.db";
> masters{ serverA; };
> };
On 11.09.09 00:21, Riccardo wrote:
> 1- If I que
I I create this configuration for my secondary server:
options {
forward only;
forwarders { serverA ; } ;
} ;
zone "example.com"{
type slave;
file "zone.db";
masters{ serverA; };
};
1- If I query to this server "example.com" (it's authoritative for
this
In message <00163646d5c2137e6b0470660...@google.com>, mrk...@gmail.com writes:
>
> I am using the configuration options shown in that faq, but I am running
> into a problem when my master server send a NOTIFY to the slaves. I have a
> zone with the same name in all four views. When the master
I am using the configuration options shown in that faq, but I am running
into a problem when my master server send a NOTIFY to the slaves. I have a
zone with the same name in all four views. When the master send a notify
for that zone to the slaves, the slave query the master to see what the
>I have 3 servers set up using bind 9.2.4-30. I am using 3 different
views and have an IP address on each slave for each view so that the
slaves >are directed to the correct zone files when contacting the
master to refresh a zone, etc. I have run into a problem with the slaves
not respecting >the i
I have 3 servers set up using bind 9.2.4-30. I am using 3 different views
and have an IP address on each slave for each view so that the slaves are
directed to the correct zone files when contacting the master to refresh a
zone, etc. I have run into a problem with the slaves not respecting th
On May 19, 2009, at 7:54 AM, Boris Dimitrov wrote:
I want to have full automatic transfer from master to slave ,
if I create slave zones manual it's not a problem for master to update
them, but i want to do this automatic if it is possible ?
Can anybody help me with this ?
I googled around but
Hi list,
I've got some confusion with BIND master/slave servers that i'm trying
to setup. First , i already have master that work well for our zones .
The problem is my slave server didn't update from master when receive
notify. all options are ok , but i got this error on slave :
rnal users can't do recursion because I'd
explicitly turned that off in the global options last year.)
Thanks Robert and Justin for taking the time to respond.
From: Jeff Lightner
Sent: Friday, March 13, 2009 4:15 PM
To: bind-users@lists.isc.org
Subj
> From: bind-users-boun...@lists.isc.org
[mailto:bind-users-boun...@lists.isc.org] On Behalf Of Jeff Lightner
Sent: Friday, March 13, 2009 16:15
To: bind-users@lists.isc.org
Subject: Internal and External view on same slave server?
> We recently decided to create intern
r the internal view which is the first
one in both named.conf files.
On doing some research I saw mention of needing to configure different
slaves for internal and external view. This mentioned need for
separate IPs.
Since I can't just build a new slave server I instead opted to
37 matches
Mail list logo