bind9 behind firewall stopped responding

2009-07-28 Thread Peter Macko
I have a master DNS (bind9) for a domain. It was working until I put it behind firewall on a DMZ private subnet. It is setup in the way that from internet the DNS maintains its original IP address, that is SAT translated by firewall to the DMZ private subnet. I allowed ports 53 TCP/UDP. Should

Creating a CNAME to another domain.

2009-07-28 Thread Ezra Taylor
Hello All: How can I create a CNAME that points to another domain. Example below. Is the below example possible? stars.mydomain.com INCNAME stars.otherdomain.com. -- Ezra Taylor ___ bind-users mailing list

Re: Bind 9.6.1: skipping zone transfer, but why ?

2009-07-28 Thread JINMEI Tatuya / 神明達哉
At Wed, 22 Jul 2009 15:56:38 +0200, Jan Hansen bi...@nhl-data.dk wrote: As I wrote in the post Master is unreachable (cached), I've switched to windows server 2003, which currently *seem* to have a positive effect. I haven't seen the behaviour yet after the switch, but Ian Tait sees this

Re: bind 9 problem with delegation

2009-07-28 Thread bsfinkel
gui gco...@gmail.com wrote: hello, i have s strange probleme with my bind server, and i hope someone could point out the problem, here is the description, i have two bind servers (replication, multi-master), bind 9.3.4, same version, same configuration (normally). I tried to do some PTR

Re: about allow-update

2009-07-28 Thread Tech W.
Hi Evan, I follow your suggestion to add the corresponding syntax into named.conf, then I run rndc reload, but got: # sbin/rndc reload rndc: connection to remote host closed This may indicate that * the remote server is using an older version of the command protocol, * this host is not

DNSSEC NS record delegation

2009-07-28 Thread Khuu, Linh MicroTech
Hi, I have question about the DNSSEC NS record. We have the parent zone, for example, example.net being signed with DNSSEC. We have a child zone test.example.net delegating to glbl.example.net as NS record. glbl.example.net is not a DNSSEC. Will nslookup for anything in test.example.net fail?

Re: Creating a CNAME to another domain.

2009-07-28 Thread Kevin Darcy
Ezra Taylor wrote: Hello All: How can I create a CNAME that points to another domain. Example below. Is the below example possible? stars.mydomain.com http://stars.mydomain.com INCNAME stars.otherdomain.com http://stars.otherdomain.com. If stars.mydomain.com

Re: Moving an AD Zone from Windows to BIND

2009-07-28 Thread Kevin Darcy
Raul Lopez Nevot wrote: What I need is a procedure that I can use to move the base zone xxx.yyy.example.com http://xxx.yyy.example.com to BIND, while keeping the six AD zones on the Windows DNS Server. If I were to define the six AD zones on the Windows DNS Server, I

Dig shows wrong ip

2009-07-28 Thread Bradley Caricofe
Hi, I recently migrated our old DNS servers to new hardware and BIND 9.6 installations. One domain is exhibiting some strangeness, dns3.potomacnetworks.com. Our main DNS servers are authoritative for this subdomain and it should point to 216.250.231.11, however, the whole world sees it pointing

Re: Dig shows wrong ip

2009-07-28 Thread sthaug
I recently migrated our old DNS servers to new hardware and BIND 9.6 installations. One domain is exhibiting some strangeness, dns3.potomacnetworks.com. Our main DNS servers are authoritative for this subdomain and it should point to 216.250.231.11, however, the whole world sees it pointing

Re: Dig shows wrong ip

2009-07-28 Thread sthaug
Here's your 216.250.243.230 address: % whois dns3.potomacnetworks.com Whois Server Version 2.0 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to http://www.internic.net for detailed information. Server Name:

Re: Dig shows wrong ip

2009-07-28 Thread Bradley Caricofe
On Tue, Jul 28, 2009 at 3:00 PM, sth...@nethelp.no wrote: Here's your 216.250.243.230 address: % whois dns3.potomacnetworks.com Whois Server Version 2.0 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to

Re: DNSSEC NS record delegation

2009-07-28 Thread Mark Andrews
In message 15aeacf110417c4b9d6186fe81fbf2d9091e0...@hq-mbx-03.ba.ad.ssa.gov, Khuu, Linh MicroTech writes: Hi, I have question about the DNSSEC NS record. We have the parent zone, for example, example.net being signed with DNSSEC. We have a child zone test.example.net delegating to

Re: Dig shows wrong ip

2009-07-28 Thread Chris Thompson
On Jul 28 2009, sth...@nethelp.no wrote: % dig +short a dns3.potomacnetworks.com @a.gtld-servers.net 216.250.243.230 As long as that host record exists, with an IP different from what your authoritative servers reply with, you are going to have problems, because queries will be answered by the

nsupdate and an external database

2009-07-28 Thread Simpson, John R
Greetings all, We have a number of BIND 9.3.4 servers that are managed by ProBIND. We would like to be able to use nsupdate to generate dynamic DNS updates, but, of course, any DDNS updates would be lost the next time the zone was pushed since they aren't reflected in ProBIND's MySQL

ISC BIND 9.6.1-P1 is now available

2009-07-28 Thread Evan Hunt
BIND 9.6.1-P1 is now available. BIND 9.6.1-P1 is a SECURITY PATCH for BIND 9.6.1. It addresses a denial-of-service bug in which a malformed UPDATE packet caused named to crash. Bugs should be reported to bind9-b...@isc.org. BIND 9.6.1-P1 can be downloaded from:

ISC BIND 9.5.1-P3 is now available

2009-07-28 Thread Evan Hunt
BIND 9.5.1-P3 is now available. BIND 9.5.1-P3 is the THIRD SECURITY PATCH for BIND 9.5.1. It addresses a denial-of-service bug in which a malformed UPDATE packet caused named to crash. Bugs should be reported to bind9-b...@isc.org. BIND 9.5.1-P3 can be downloaded

ISC BIND 9.4.3-P3 is now available

2009-07-28 Thread Evan Hunt
BIND 9.4.3-P3 is now available. BIND 9.4.3-P3 is the THIRD SECURITY PATCH for BIND 9.4.3. It addresses a denial-of-service bug in which a malformed UPDATE packet caused named to crash. Bugs should be reported to bind9-b...@isc.org. BIND 9.4.3-P3 can be downloaded

Re: Moving an AD Zone from Windows to BIND

2009-07-28 Thread Michael Milligan
bsfin...@anl.gov wrote: I am not worried about the DHCP piece. There are two zones I have to convert. One is mostly static and contains Windows Servers. The other is dynamic, with client machines under the control of a Windows DHCP server. For this zone, we will change DHCP to static

Re: Moving an AD Zone from Windows to BIND

2009-07-28 Thread Mark Andrews
In message 20090728175246.bf0a817...@britaine.cis.anl.gov, bsfin...@anl.gov writes: I do not want any dynamic DNS to my BIND servers, as I am not sure how that DDNS would interface with DNSSEC. DNSSEC is easier with a DDNS zone than a non-DDNS zone as named can ensure the signatures get

Re: Moving an AD Zone from Windows to BIND

2009-07-28 Thread Mark Andrews
Mark Andrews writes: In message 20090728175246.bf0a817...@britaine.cis.anl.gov, bsfin...@anl.gov writes: I do not want any dynamic DNS to my BIND servers, as I am not sure how that DDNS would interface with DNSSEC. DNSSEC is easier with a DDNS zone than a non-DDNS zone as named can

Re: Creating a CNAME to another domain.

2009-07-28 Thread Ezra Taylor
Thanks all. On Fri, Jul 24, 2009 at 2:57 PM, Ezra Taylor ezra.tay...@gmail.com wrote: Hello All: How can I create a CNAME that points to another domain. Example below. Is the below example possible? stars.mydomain.com INCNAME stars.otherdomain.com. -- Ezra

Re: Moving an AD Zone from Windows to BIND

2009-07-28 Thread Gordon A. Lang
For what it's worth, we moved 100% of all our DNS from MS DNS to BIND. Doing so solved the problem of the MS DNS servers periodically (randomly) losing critical glue records. It also eliminated the need for 6 pairs of DNS servers to support the 6 independent domains, each needing to own the

Binding on addresses

2009-07-28 Thread Chris Hills
Hi After changing configuration from listen-on-v6 { any; }; to using specific addresses, I observed the following in the log after issuing `rndc reload` (times are CEST):- 29-Jul-2009 04:44:22.893 network: error: binding TCP socket: address in use 29-Jul-2009 04:44:22.893 network: error:

Re: Creating a CNAME to another domain.

2009-07-28 Thread Danny Mayer
Kevin Darcy wrote: Ezra Taylor wrote: Hello All: How can I create a CNAME that points to another domain. Example below. Is the below example possible? stars.mydomain.com http://stars.mydomain.com INCNAME stars.otherdomain.com http://stars.otherdomain.com.

Re: about tcp port 53

2009-07-28 Thread Tech W.
--- On Tue, 28/7/09, Stephane Bortzmeyer bortzme...@nic.fr wrote: what's the use of bind's tcp port 53? DNS requests and responses. oh, I was always thinking dns requests and responses are going with udp protocal. under what condition it uses tcp protocal? Regards, Wah.