Personally I would be looking for why there is such a big round trip times even to Google.
PING 8.8.8.8 (8.8.8.8): 56 data bytes 64 bytes from 8.8.8.8: icmp_seq=0 ttl=57 time=16.654 ms 64 bytes from 8.8.8.8: icmp_seq=1 ttl=57 time=18.336 ms % traceroute -In 8.8.8.8 traceroute to 8.8.8.8 (8.8.8.8), 64 hops max, 72 byte packets 1 172.30.42.97 1.117 ms 0.870 ms 0.852 ms 2 * * * 3 * * * 4 * * * 5 59.154.142.28 13.654 ms 19.100 ms 11.059 ms 6 72.14.223.66 10.939 ms 13.051 ms 19.474 ms 7 216.239.40.223 11.156 ms 10.756 ms 11.680 ms 8 216.239.41.1 13.082 ms 19.892 ms 11.985 ms 9 8.8.8.8 10.721 ms 13.203 ms 11.703 ms % Do this for all but you local server and then work out where the slow path is. Mark In message <17a5a589-5f76-45da-8d55-b928916ae...@rrcic.com>, "John W. Blue" wri tes: > Pol, > > You can "audit" your traffic by getting a pcap via tcpdump and then analyzi= > ng it in wireshark. Packets don't lie. > > John > > Sent from Nine<http://www.9folders.com/> > > From: Pol Hallen <bin...@fuckaround.org> > Sent: Sep 21, 2016 2:35 PM > To: bind-users@lists.isc.org > Subject: Re: forwarder (YES/NO) > > hello again! > > > try running dig +trace <host> and see how fast it runs. It should return > > in about same time as BIND does (when it doesn't have anything in cache). > > ; <<>> DiG 9.10.3-P4-Debian <<>> +trace @192.168.1.212 yahoo.it > ; (1 server found) > ;; global options: +cmd > . 518367 IN NS d.root-servers.net. > . 518367 IN NS g.root-servers.net. > . 518367 IN NS e.root-servers.net. > . 518367 IN NS h.root-servers.net. > . 518367 IN NS b.root-servers.net. > . 518367 IN NS c.root-servers.net. > . 518367 IN NS a.root-servers.net. > . 518367 IN NS l.root-servers.net. > . 518367 IN NS i.root-servers.net. > . 518367 IN NS m.root-servers.net. > . 518367 IN NS k.root-servers.net. > . 518367 IN NS j.root-servers.net. > . 518367 IN NS f.root-servers.net. > . 518396 IN RRSIG NS 8 0 518400 > 20161004170000 20160921160000 46551 . > tZptpyBClVtkAbyo4NOR2MgHDoq67TlImcBVzZORhn7C2c557prmG42J > sSPD8aZmisk3bbUJbmqFVFB/M2y/O4zjw3jBf42ujHce99VD3xCeJuk7 > boGW356J6c7JaApB02GRf3SGQIv7x6MVyBmGeKxAosEePlbfjg/8NPEY +y0=3D > ;; Received 397 bytes from 192.168.1.212#53(192.168.1.212) in 2 ms > > it. 172800 IN NS a.dns.it. > it. 172800 IN NS m.dns.it. > it. 172800 IN NS r.dns.it. > it. 172800 IN NS dns.nic.it. > it. 172800 IN NS nameserver.cnr.it. > it. 86400 IN NSEC itau. NS RRSIG NSEC > it. 86400 IN RRSIG NSEC 8 1 86400 > 20161004170000 20160921160000 46551 . > LL0eXWf22Lhhi5C0P+PX446JQH+GwCFhxU7tkUUF9wyG+pQ0eDCnpTu0 > vm0ww/3YycmNJwlF3IHJmLIh2l7htSW6G/o2/ozNbZU6RF9pMhKxQNrJ > aE6hf4L+Ka1N5uNstgJzrE6pV9ouXOJmL0Epoa3gUnbSZcFHH5QrKbu6 AfQ=3D > ;; Received 545 bytes from 192.58.128.30#53(j.root-servers.net) in 577 ms > > yahoo.it. 10800 IN NS ns2.yahoo.com. > yahoo.it. 10800 IN NS ns1.yahoo.com. > yahoo.it. 10800 IN NS ns5.yahoo.com. > yahoo.it. 10800 IN NS ns7.yahoo.com. > yahoo.it. 10800 IN NS ns3.yahoo.com. > ;; Received 136 bytes from 194.0.16.215#53(a.dns.it) in 136 ms > > yahoo.it. 300 IN A 106.10.212.24 > yahoo.it. 300 IN A 98.137.236.24 > yahoo.it. 300 IN A 77.238.184.24 > yahoo.it. 300 IN A 212.82.102.24 > yahoo.it. 300 IN A 74.6.50.24 > yahoo.it. 86400 IN NS ns3.yahoo.com. > yahoo.it. 86400 IN NS ns2.yahoo.com. > yahoo.it. 86400 IN NS ns1.yahoo.com. > yahoo.it. 86400 IN NS ns4.yahoo.com. > yahoo.it. 86400 IN NS ns5.yahoo.com. > ;; Received 380 bytes from 68.180.131.16#53(ns1.yahoo.com) in 173 ms > > same problem... bind is too slow... > > the situation change (very fast) if I use bind like resolver > > forwarders { > 8.8.8.8; > } > > I don't understand why without resolver my bind is so slow... how I can > audit the problem? > > thanks! :-) > > >> but testing 127.0.0.1, bind keep also 4000/5000ms to resolve a query > > > > > >> forwarders { > >> 127.0.0.1; > >> } > > > > do you forward to yourself??? > > unfortunately looking for bind on internet there're many wrong howto :-/ > > Pol > _______________________________________________ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscri= > be from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users > > --_000_17a5a5895f7645da8d55b928916ae5farrciccom_ > Content-Type: text/html; charset="us-ascii" > Content-Transfer-Encoding: quoted-printable > > <html> > <head> > <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > > > <meta name=3D"Generator" content=3D"Microsoft Exchange Server"> > <!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; pad= > ding-left: 4pt; border-left: #800000 2px solid; } --></style> > </head> > <body> > <div> > <div style=3D"font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12p= > t"> > <div>Pol,</div> > <div><br> > </div> > <div>You can "audit" your traffic by getting a pcap via tcpdump a= > nd then analyzing it in wireshark. Packets don't lie.</div> > <div><br> > </div> > <div>John</div> > <div><br> > </div> > <div id=3D"x_signature-x" style=3D"">Sent from <a href=3D"http://www.9folde= > rs.com/" style=3D"text-decoration:none; color:#009BDF"> > Nine</a></div> > </div> > <div id=3D"x_quoted_header" style=3D"clear:both"><br> > <div style=3D"border:none; border-top:solid #E1E1E1 1.0pt; padding:3.0pt 0c= > m 0cm 0cm"> > <span style=3D"font-size:11.0pt; font-family:'Calibri','sans-serif'"><b>Fro= > m:</b> Pol Hallen <bin...@fuckaround.org><br> > <b>Sent:</b> Sep 21, 2016 2:35 PM<br> > <b>To:</b> bind-users@lists.isc.org<br> > <b>Subject:</b> Re: forwarder (YES/NO)<br> > </span></div> > </div> > <br type=3D"attribution"> > </div> > <font size=3D"2"><span style=3D"font-size:10pt;"> > <div class=3D"PlainText">hello again!<br> > <br> > > try running dig +trace <host> and see how fast it runs. It s= > hould return<br> > > in about same time as BIND does (when it doesn't have anything in cach= > e).<br> > <br> > ; <<>> DiG 9.10.3-P4-Debian <<>> +trace @192.16= > 8.1.212 yahoo.it<br> > ; (1 server found)<br> > ;; global options: +cmd<br> > . &n= > bsp; 518367 IN&= > nbsp; NS d.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS g.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS e.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS h.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS b.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS c.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS a.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS l.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS i.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS m.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS k.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS j.root-serve= > rs.net.<br> > . &n= > bsp; 518367 IN&= > nbsp; NS f.root-serve= > rs.net.<br> > . &n= > bsp; 518396 IN&= > nbsp; RRSIG NS 8 0 518400 <br> > 20161004170000 20160921160000 46551 . <br> > tZptpyBClVtkAbyo4NOR2MgHDoq67TlImcBVzZORhn7C2c557prmG42J <br> > sSPD8aZmisk3bbUJbmqFVFB/M2y/O4zjw3jBf42ujHce99VD3xCeJuk7 <br> > boGW356J6c7JaApB02GRf3SGQIv7x6MVyBmGeKxAosEePlbfjg/8NPEY +y0=3D<br> > ;; Received 397 bytes from 192.168.1.212#53(192.168.1.212) in 2 ms<br> > <br> > it. = > 172800 IN  = > ; NS a.dns.it.<br> > it. = > 172800 IN  = > ; NS m.dns.it.<br> > it. = > 172800 IN  = > ; NS r.dns.it.<br> > it. = > 172800 IN  = > ; NS dns.nic.it.<br> > it. = > 172800 IN  = > ; NS nameserver.cnr.it.<br> > it. = > 86400 IN = > NSEC itau. NS RRSIG NSEC<br> > it. = > 86400 IN = > RRSIG NSEC 8 1 86400 <br> > 20161004170000 20160921160000 46551 . <br> > LL0eXWf22Lhhi5C0P+PX446JQH+GwCFhxU7tkUUF9wyG+pQ0eDCnpTu0 <br> > vm0ww/3YycmNJwlF3IHJmLIh2l7htSW6G/o2/ozNbZU6RF9pMhKxQNrJ <br> > aE6hf4L+Ka1N5uNstgJzrE6pV9ouXOJmL0Epoa3gUnbSZcFHH5QrKbu6 AfQ=3D<br> > ;; Received 545 bytes from 192.58.128.30#53(j.root-servers.net) in 577 ms<b= > r> > <br> > yahoo.it. = > 10800 IN NS&nb= > sp; ns2.yahoo.com.<br> > yahoo.it. = > 10800 IN NS&nb= > sp; ns1.yahoo.com.<br> > yahoo.it. = > 10800 IN NS&nb= > sp; ns5.yahoo.com.<br> > yahoo.it. = > 10800 IN NS&nb= > sp; ns7.yahoo.com.<br> > yahoo.it. = > 10800 IN NS&nb= > sp; ns3.yahoo.com.<br> > ;; Received 136 bytes from 194.0.16.215#53(a.dns.it) in 136 ms<br> > <br> > yahoo.it. = > 300 IN &n= > bsp; A 106.10.212.24<br> > yahoo.it. = > 300 IN &n= > bsp; A 98.137.236.24<br> > yahoo.it. = > 300 IN &n= > bsp; A 77.238.184.24<br> > yahoo.it. = > 300 IN &n= > bsp; A 212.82.102.24<br> > yahoo.it. = > 300 IN &n= > bsp; A 74.6.50.24<br> > yahoo.it. = > 86400 IN NS&nb= > sp; ns3.yahoo.com.<br> > yahoo.it. = > 86400 IN NS&nb= > sp; ns2.yahoo.com.<br> > yahoo.it. = > 86400 IN NS&nb= > sp; ns1.yahoo.com.<br> > yahoo.it. = > 86400 IN NS&nb= > sp; ns4.yahoo.com.<br> > yahoo.it. = > 86400 IN NS&nb= > sp; ns5.yahoo.com.<br> > ;; Received 380 bytes from 68.180.131.16#53(ns1.yahoo.com) in 173 ms<br> > <br> > same problem... bind is too slow...<br> > <br> > the situation change (very fast) if I use bind like resolver<br> > <br> > forwarders {<br> > 8.8.8.8;<br> > }<br> > <br> > I don't understand why without resolver my bind is so slow... how I can <br= > > > audit the problem?<br> > <br> > thanks! :-)<br> > <br> > >> but testing 127.0.0.1, bind keep also 4000/5000ms to resolve a que= > ry<br> > ><br> > ><br> > >> forwarders {<br> > >> 127.0.0.1;<br> > >> }<br> > ><br> > > do you forward to yourself???<br> > <br> > unfortunately looking for bind on internet there're many wrong howto :-/<br= > > > <br> > Pol<br> > _______________________________________________<br> > Please visit <a href=3D"https://lists.isc.org/mailman/listinfo/bind-users">= > https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from t= > his list<br> > <br> > bind-users mailing list<br> > bind-users@lists.isc.org<br> > <a href=3D"https://lists.isc.org/mailman/listinfo/bind-users">https://lists= > .isc.org/mailman/listinfo/bind-users</a><br> > </div> > </span></font> > </body> > </html> > > --_000_17a5a5895f7645da8d55b928916ae5farrciccom_-- > > --===============4515816377316874877== > Content-Type: text/plain; charset="us-ascii" > MIME-Version: 1.0 > Content-Transfer-Encoding: 7bit > Content-Disposition: inline > > _______________________________________________ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users > --===============4515816377316874877==-- -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users