Re: windows client request timed out

2015-06-22 Thread Fr34k
Put a dot at the end of the query hostname so that Windows doesn't add whatever the domain name suffix/es the Windows client may be configured with.That is,   nslookup google.com. It may be the case that the windows client is adding whatever domain name suffix/es it has been configured with

Re: ASSERT messages

2014-04-10 Thread Fr34k
Maybe this: 3212. [bug] rbtdb.c: failed to remove a node from the deadnodes list prior to adding a reference to it leading a possible assertion failure. [RT #23219] source: ftp://ftp.isc.org/isc/bind9/9.8.6/CHANGES Note:  I stopped

Re: BIND 9.9.1-P4 is now available

2012-10-26 Thread Fr34k
To: Fr34k freaknet...@yahoo.com Cc: Bindlist bind-us...@isc.org Sent: Thursday, October 25, 2012 3:29 PM Subject: Re: BIND 9.9.1-P4 is now available Let me define what hung means in our experience:  We find that named is running but will not respond to queries, rndc status will respond

Re: BIND 9.9.1-P4 is now available

2012-10-25 Thread Fr34k
Hello, We are finding several of our recursive BIND 9.9.1-P3 servers (on Solaris 10 OS) hung and I want to be able to qualify the symptoms in order to convince others that P4 (or 9.9.2?) will (or will not) address this. Let me define what hung means in our experience:  We find that named is

Re: BIND 9.9.1-P4 is now available

2012-10-25 Thread Fr34k
. From: Fr34k freaknet...@yahoo.com To: Bindlist bind-us...@isc.org Sent: Thursday, October 25, 2012 9:51 AM Subject: Re: BIND 9.9.1-P4 is now available Hello, We are finding several of our recursive BIND 9.9.1-P3 servers (on Solaris 10 OS) hung and I want

Re: BIND 9.9.1-P4 is now available

2012-10-25 Thread Fr34k
Hello Jeremy, Thank you for your reply. Let me define what hung means in our experience:  We find that named is running but will not respond to queries, rndc status will respond with output but that output shows that named is not processing any queries (see below), other rndc commands

Re: A lot of queries from a customer.

2012-07-17 Thread Fr34k
We have been monitoring the same. Google found an unrelated, yet similar, issue a few years ago:  http://pages.cs.wisc.edu/~plonka/netgear-sntp/#ToC16 From: Rafael Molina rafael.mol...@interlink.net.ve To: bind-users@lists.isc.org Sent: Thursday, June 28,

Re: Loaded zone files query

2012-07-10 Thread Fr34k
rndc status Is this a trick question? From: Kirk Hoganson kirkhogan...@gmail.com To: bind-users@lists.isc.org Sent: Tuesday, July 10, 2012 3:22 PM Subject: Loaded zone files query Does anyone know of a simple way to discover how many zone files bind has

Re: Loaded zone files query

2012-07-10 Thread Fr34k
: X x=number of zones listed in named.conf + any automatically added zones not quite what he's asking for, but I've not been able to find a better answer either. On Tue, 10 Jul 2012, Fr34k wrote: rndc status Is this a trick question? From: Kirk Hoganson

Re: Delegation bit-rot detection?

2012-06-14 Thread Fr34k
We are exploring similar audits and opportunities for cleanup. For domains we delegate PTRs, we track NS hostnames (e.g. IN NS  ns1.bogus.customer.tld) that have gone NXDOMAIN. If ns1.bogus.customer.tld remains NXDOMAIN for 30+ days, we remove the delegation. The idea behind 30+ days is to

Re: Exclude a domain from DNSSEC validation, like Unbound's domain-insecure.

2012-04-26 Thread Fr34k
Great question (Augie) and great feedback (JP). As DNSSEC is adopted, some type of mitigation process will be welcomed. For that reason, I think this is on topic. From: Jan-Piet Mens jpmens@gmail.com To: bind-users@lists.isc.org Sent: Thursday, April

9.9.x Train Inquiry for ISC

2012-04-24 Thread Fr34k
Dear ISC et al., Within the last month, we've seen new versions for the 9.8.x, 9.7.x, and 9.6.x trains. http://www.isc.org/software/bind/versions Should we expect a 9.9.0 update in the near future (e.g., 9.9.1)? Any status would be appreciated. Thank you for all your support!

Re: SERVFAIL with ocsp.entrust.net.

2012-04-24 Thread Fr34k
Perhaps provide the ocsp.entrust.net folks 3rd party evaluation tool(s) to identify areas of concerns? For example, here are two: http://www.dnsvalidation.com/reports/4f96bdec7d79ee78db44 http://www.intodns.com/ocsp.entrust.net These find more than one critical item to fix. Why is

Re: DNS Amplification Attack Mitigation

2012-03-13 Thread Fr34k
Hello, Did I miss any feedback on this, or perhaps there isn't any to offer (?) Thank you. From: Fr34k freaknet...@yahoo.com To: Bindlist bind-us...@isc.org Sent: Friday, March 9, 2012 10:30 AM Subject: DNS Amplification Attack Mitigation All, I am (we

max-cache-ttl usage and best-practices

2012-03-13 Thread Fr34k
Hi All, I wanted some feedback on max-cache-ttl usage and best-practices, please. The BIND 9 ARM says: max-cache-ttl Sets the maximum time for which the server will cache ordinary (positive) answers. The default is one week (7 days). A value of zero may cause all queries to return

DNS Amplification Attack Mitigation

2012-03-09 Thread Fr34k
All, I am (we all are (?)) interested in techniques for mitigating DNS amplification attacks for both recursive and authoritative BIND servers (versions 9.x). Google found http://www.secureworks.com/research/threats/dns-amplification/ and

Re: variable dig results

2012-01-06 Thread Fr34k
I suspect that dig is confused.  Let me explain. Looks like WHOIS says that these (2) servers are authoritative for this domain: ns1.thehartford.com.   ['162.136.188.1']   [TTL=172800] ns2.thehartford.com.   ['162.136.190.1']   [TTL=172800] However, the DNS configuration says something

Trouble looking up dacspro.com

2011-12-23 Thread Fr34k
Hello, Having trouble looking up dacspro.com. This domain has three NS servers, one of which is not responding (ns02) to my queries. dacspro.com.    172800  IN  NS  ns01.gnenc.org. dacspro.com.    172800  IN  NS  ns02.gnenc.org. dacspro.com.    172800 

Re: Trouble looking up dacspro.com

2011-12-23 Thread Fr34k
Disregard.  PEBKAC issue. Happy Holidays. - Original Message - From: Fr34k To: Bindlist bind-us...@isc.org Cc: Sent: Friday, December 23, 2011 2:09 PM Subject: Trouble looking up dacspro.com Hello, Having trouble looking up dacspro.com. This domain has three NS servers

Re: Question About max-clients-per-query

2011-11-18 Thread Fr34k
Hello, Read the BIND ARM (Admin Ref. Manual) about these settings, but here is an example of what I use:     clients-per-query 10 ;     max-clients-per-query 20 ; http://www.isc.org/software/bind/documentation Previously, this resource was posted on this list which is good info to

Re: DNS Sinkhole in BIND

2011-10-17 Thread Fr34k
http://www.sans.org/reading_room/whitepapers/dns/dns-sinkhole_33523 Perhaps the above link target may help. Thanks. From: Lightner, Jeff jlight...@water.com To: Ryan Novosielski novos...@umdnj.edu; babu dheen babudh...@yahoo.co.in; Bind Users Mailing List

Re: named crashed (mem.c:1099: INSIST(ctx-stats[i].gets == 0U) failed)

2011-05-05 Thread Fr34k
Hello All, Thanks Evan. Should the Community expect a BIND 9.7.3 train update/maintenance release which, among other things, addresses this mem.c issue? If so, any ETA? It is not my intent to sound pushy. Let me explain. We were in the process of rolling 9.7.3 out but we stopped figuring a

Re: BIND 9.7 behavior - lack of response causes

2011-04-05 Thread Fr34k
- Original Message From: Mark Andrews ma...@isc.org To: Fr34k freaknet...@yahoo.com Cc: Bindlist bind-us...@isc.org Sent: Mon, April 4, 2011 9:02:35 PM Subject: Re: BIND 9.7 behavior - lack of response causes What do you have lame-ttl set to? I don't. That is, I don't have

BIND 9.7 behavior - lack of response causes

2011-04-04 Thread Fr34k
Hello, Given: BIND 9.7.2-P2 on Solaris 10. For about an hour, I had a network event where a caching DNS server could not get recursive queries back from authoritative DNS servers on the Internet. Obviously, this is a problem. Moreover, the authority for our most popular hostnames have set

Re: Q on clients-per-query, max-clients-per-query

2011-03-24 Thread Fr34k
- Original Message From: Mark Andrews To: Fr34k Cc: Bindlist Sent: Wed, March 23, 2011 9:04:00 PM Subject: Re: Q on clients-per-query, max-clients-per-query In message , Fr34k writes: Hello, # The ARM says: # clients-per-query, max-clients-per-query These set

Q on clients-per-query, max-clients-per-query

2011-03-23 Thread Fr34k
Hello, # The ARM says: # clients-per-query, max-clients-per-query These set the initial value (minimum) and maximum number of recursive simultaneous clients for any given query (qname,qtype,qclass) that the server will accept before dropping additional clients. named will attempt to self tune

Re: [OT] does deliveragent must have a PTR RR

2011-02-01 Thread Fr34k
See RFC1123 and RFC1912 which suggest that legitimate nodes on the Internet have appropriate forward/reverse DNS entries. By appropriate, I mean DNS entires which distinguish which hosts are static/business space from residential/dhcp space. Reason: So others on the Internet can make informed

Re: out of place mx records.

2010-10-28 Thread Fr34k
- Original Message From: Mark Andrews ma...@isc.org To: Barry Margolin bar...@alum.mit.edu Cc: comp-protocols-dns-b...@isc.org Sent: Thu, October 28, 2010 9:49:46 PM Subject: Re: out of place mx records. In message barmar-ed15c5.21262028102...@news.eternal-september.org,

Re: Notice regarding BIND 9.7.2

2010-09-28 Thread Fr34k
I was about to ask again, but figured I had better check isc.org first. Behold: http://www.isc.org/software/bind/972-p2 FYI. Thanks. - Original Message From: Hauke Lampe la...@hauke-lampe.de To: Larissa Shapiro laris...@isc.org; bind-us...@isc.org Sent: Mon, September 27, 2010

Re: Notice regarding BIND 9.7.2

2010-09-27 Thread Fr34k
Hello, Were there ... more information on these developments early next week? My apologies if I missed them. Thank you. - Original Message From: Larissa Shapiro laris...@isc.org To: bind-us...@isc.org Sent: Sun, September 19, 2010 5:54:15 PM Subject: Notice regarding BIND 9.7.2

Re: bind multi-threaded question

2010-04-28 Thread Fr34k
Hello, http://en.wikipedia.org/wiki/Process_%28computing%29 may help to explain what is going on. HTH From: max power el_shersh...@hotmail.com To: bind-users@lists.isc.org Sent: Wed, April 28, 2010 4:38:06 AM Subject: bind multi-threaded question Hi i

Re: Apparent BIND problem doing RBL lookups for Postfix

2010-04-15 Thread Fr34k
Hello, Looks like NXDOMAIN can be one of the responses. http://www.spamhaus.org/faq/answers.lasso?section=DNSBL%20Usage#252 That said, I think it is working correctly (a la name=33.229.242.205.zen.spamhaus.org type=A: Host not found, try again). However, perhaps tweak the number of

Re: Bind Clustering

2010-04-08 Thread Fr34k
Hello, We used rsync to copy our master/primary data to the secondary servers. Using some script magic, the primary is still the master (via named.conf) since, as with most DBs, there can only be one source of truth. However, the secondary servers were almost mirror copies of the primary. Only

Re: Using an MX record from a different domain

2010-03-30 Thread Fr34k
Hello, named-checkzone is warning you that the MX has a different FQDN than the zone it is in. This is fine so long as the out of zone MX record is valid, but named-checkzone wants you to know that it can't verify for sure. So, it is a heads up message and why the ultimate response is OK. I

Re: Reverse DNS on a /27 delegation and zone files

2010-03-29 Thread Fr34k
Hello, Sufficient resources on the Internet may be helpful. For example, http://www.indelible.org/ink/classless/ Searching for RFC2317 or classless in-addr.arpa delegation may result in additional references. Hope this helps. - Original Message From: Alex mysqlstud...@gmail.com To:

Re: what is a SPF (type 99) record and who do I implement?

2010-03-24 Thread Fr34k
http://www.openspf.org/ is pretty good. Not only does it build the file for you, but it can test your live record. From: Security Admin (NetSec) secad...@netsecdesign.com To: bind-users@lists.isc.org bind-users@lists.isc.org Sent: Wed, March 24, 2010 4:26:46

Re: blockhole'd IP receiving referral?

2009-12-19 Thread Fr34k
Hello, Chris, I believe you are correct. That is, blackhole applies to the sending of queries in addition to the receiving of queries. Let me explain. I discovered this the hard way. I had a /24 in the blackhole because it contained abusive clients. Within this /24 sat two legitimate

BIND 9.x and hint file

2009-08-31 Thread Fr34k
Hi All, I thought with some version of BIND 9, one no longer needed a root hints file. I can't recall the details and my google searches are finding how to set up a hints file (instead of suggesting this is, say, deprecated). Can someone shed some light on this? Thanks

Re: BIND 9.x and hint file

2009-08-31 Thread Fr34k
That's exactly what I was recalling -- thanks for your time and response Mr. Reed. - Original Message From: Jeremy C. Reed jr...@isc.org To: Fr34k freaknet...@yahoo.com Cc: Bindlist bind-us...@isc.org Sent: Monday, August 31, 2009 12:37:05 PM Subject: Re: BIND 9.x and hint file

Re: BIND 9.x and hint file

2009-08-31 Thread Fr34k
Thank you Chris! This is what I was looking for. - Original Message From: Chris Thompson c...@cam.ac.uk To: Fr34k freaknet...@yahoo.com Cc: Bind Users Mailing List bind-users@lists.isc.org Sent: Monday, August 31, 2009 12:33:57 PM Subject: Re: BIND 9.x and hint file On Aug 31 2009

Re: about tcp port 53

2009-07-29 Thread Fr34k
Hello, Doing a search on this at www.google.com offers this first link: http://www.tcpipguide.com/free/t_DNSMessageGenerationandTransport-2.htm HTH - Original Message From: Tech W. tech...@yahoo.com.cn To: Stephane Bortzmeyer bortzme...@nic.fr Cc: bind-users@lists.isc.org Sent:

Re: Truncated, retrying in TCP on Reverse lookup

2009-07-09 Thread Fr34k
                                                                                                    Fr34k wrote: Hello,   As I understand it, there are so many PTRs for that IP address, that DNS will change protocol from UDP to TCP. So, the message you are getting is informational because of this protocol change. See the long list of PTRs below

Re: bind 9.6.1 under perform after running for a couple of hours

2009-07-08 Thread Fr34k
Hello, A few of the default settings changed from 9.4.x to 9.6.x The appropriate README files, change logs, and BIND ARM will provide details about them. Below are some options and logging configurations you may want to investigate. Ye Ole Disclaimer: Please be sure to understand what these do

Re: SPF/TXT records

2009-06-19 Thread Fr34k
Hello, Do I dare comment on this? Okay, I do... RE: Advogato: If security was easy and conveinent, then everything would be secure. Someone tell Advogato! Advogato is complaining because they want an unmanagable environment of dynamic outbound relays and expect SPF, static DNS records, to

Re: Make changes en mass

2009-03-24 Thread Fr34k
Hello, Some folks prefer to script something. Some may find this tool helpful: http://www.laffeycomputer.com/rpl.html I'm sure there are other ways. HTH - Original Message From: John D. Vo j...@eagle.net To: bind-users@lists.isc.org Sent: Tuesday, March 24, 2009 1:03:22 PM Subject:

Re: DNS server can resolve some domains - BIND 9.4.2-P1

2009-02-26 Thread Fr34k
For Solaris9 kernal tunables, this may help: http://docs.sun.com/app/docs/doc/816-7137/6md5pauj7?l=ena=view But note that in my experience BIND 9.4.x will not use these OS limits, but what how many FDs have compiled BIND with. For our purposes, 9.5.1b2 worked great on Solaris9 We are now

Re: SERVFAIL issues

2009-01-16 Thread Fr34k
Hello, Has the max-cache-size setting in named.conf been considered? If not, note that in early releases of 9.5.x max-cache-size is 32M by default instead of unlimited as in 9.4.x From the CHANGES file with the bind-9.5.0-P2 source: max-cache-size defaults to 32M Using: max-cache-size 0 ;

9.5.1b2 rbtdb.c assertion failure

2008-12-31 Thread Fr34k
Hello, Running 9.5.1b2 on Solaris9. Crashed with this info: Dec 31 13:04:25 named[308]: [ID 873579 daemon.crit] rbtdb.c:1482: REQUIRE((node)-references 0) failed Dec 31 13:04:25 named[308]: [ID 873579 daemon.crit] exiting (due to assertion failure) Dec 31 13:05:07 genunix: [ID 603404