Re: BIND 9.10.0b1 has been released.

2014-02-26 Thread G.W. Haywood
Hi there, On Wed, 26 Feb 2014, Michael McNally wrote: At ISC we are quite excited about the long list of new features and ... I don't want to rain on your parade, and I know that this is likely to be contentious, but I would just like to ask all at ISC (and I know it isn't necessary, but

retransfer zone from stealth master

2014-02-26 Thread Lawrence K. Chen, P.Eng.
Noticed some zones weren't transferring, so I tried to see what was up. The logs show its polling the published master (one of my secondaries), which fails since it doesn't have the zone yet. None of my secondaries have it yet. I was on vacation when the domains were set up, though I had

Re: retransfer zone from stealth master

2014-02-26 Thread Phil Mayers
On 26/02/14 14:57, Lawrence K. Chen, P.Eng. wrote: How can I get an initial transfer of the zone from a stealth master? Or do I have to wait to get the administrator of the master to give it another kick? rndc retransfer? ___ Please visit

Re: BIND 9.10.0b1 has been released.

2014-02-26 Thread Evan Hunt
On Wed, Feb 26, 2014 at 12:44:37PM +, G.W. Haywood wrote: Many of us seek no excitement at all in our working day. We're here for you, too. BIND 9.9 is an extended support version, it won't reach end-of-life until at least 2017, and we won't add new features to it unless there's a darned

Re: bind-users Digest, Vol 1773, Issue 1

2014-02-26 Thread Barry S. Finkel
Lawrence K. Chen, P.Eng. lkc...@ksu.edu wrote: Hmmm, so that explains what I'm seeing in my logs of my nameservers getting hammered by AD. Should I be worried? Is there anything that could be done on my end to help reduce the impact? On our campus, we have always allowed delegation of

Re: retransfer zone from stealth master

2014-02-26 Thread Lawrence K. Chen, P.Eng.
Guess I had something wrong in my named.conf, just now 'rndc retransfer' worked, because after some change at 2:04pm it tried more IPsincluding the actual master I suppose I should've expected to see it continue to attempt to refresh the zone, as it started doing for another zone I had

Re: BIND 9.10.0b1 has been released.

2014-02-26 Thread Lawrence K. Chen, P.Eng.
On 02/26/14 10:01, Evan Hunt wrote: On Wed, Feb 26, 2014 at 12:44:37PM +, G.W. Haywood wrote: Many of us seek no excitement at all in our working day. We're here for you, too. BIND 9.9 is an extended support version, it won't reach end-of-life until at least 2017, and we won't add new

Re: BIND 9.10.0b1 has been released.

2014-02-26 Thread David Ford
On 02/26/2014 05:48 PM, Lawrence K. Chen, P.Eng. wrote: Except that security patches haven't been going into BIND 4 for some time probably because BIND4 has been deprecated since 2007. BIND8 was deprecated in 2008. BIND 9.4 was deprecated in 2008 with the last release of 9.4-ESV in 2012. the

Bind vs flood

2014-02-26 Thread Dmitry Rybin
Over 2 weeks ago begins flood. A lot of queries: niqcs.www.84822258.com vbhea.www.84822258.com abpqeftuijklm.www.84822258.com adcbefmzidmx.www.84822258.com and many others. Bind answers with Server failure. On high load (4 qps) all normal client can get Servfail on good query. Or query can

Re: Bind vs flood

2014-02-26 Thread Peter Andreev
Hi Dmitry, If your problem is a lot of strange queries, then there is two ways: 1. You operate an open resolver. If you can - restrict it to a limited scope of clients, otherwise the only way you can lower number of incoming queries is DPI; 2. You operate a non-open resolver. Then you can find