RE: Getting all IP adresses for a domain name

2020-01-29 Thread Lightner, Jeffrey
"dig +trace " will show the whole path to a given record from root servers down through registrar to the name servers the registrar specifies. From: bind-users On Behalf Of Leroy Tennison Sent: Wednesday, January 29, 2020 2:13 PM To: bind-users@lists.isc.org Subject: Getting all IP adresses

RE: RHEL, Centos, Fedora rpm 9.14.6

2019-09-30 Thread Lightner, Jeffrey
I can't speak for him but will say Carl has been providing these packages and announcing them on this list for quite some time now and it is valuable to those who would like to use later upstream packages on RHEL/CentOS/Fedora. RHEL's model (and therefore CentOS') is to start with a base

RE: Bind 9 with Views: zone transfer refused from master to slave

2019-07-03 Thread Lightner, Jeffrey
You have to use separate IPs for the separate views on the master and the slave. Here we just put alias IPs on the primary interfaces and use those for the second view. From: bind-users On Behalf Of Roberto Carna Sent: Wednesday, July 03, 2019 3:21 PM To: ML BIND Users Subject: Bind 9 with

RE: A policy for removing named.conf options.

2019-06-13 Thread Lightner, Jeffrey
But if the knob goes to 11 you'll know it is superior to those that only go to 10. :-) -Original Message- From: bind-users On Behalf Of Warren Kumari Sent: Thursday, June 13, 2019 2:53 PM To: Evan Hunt Cc: Ondřej Surý ; comp-protocols-dns-b...@isc.org Subject: Re: A policy for

RE: A policy for removing named.conf options.

2019-06-13 Thread Lightner, Jeffrey
Systemd writes logs for things it starts to the Journal which can be viewed with journalctl command. On some distros (e.g. RHEL7) it also continues to write many things to system logs like /var/log/messages. Not all of what goes to the Journal is in /var/log/messages but all of what is in

RE: A policy for removing named.conf options.

2019-06-13 Thread Lightner, Jeffrey
I'd suggest also giving warnings for deprecated options when running named-checkconf (and named-checkzone if applicable). You mention the logs but not the commands. Jeffrey C. Lightner Sr. UNIX/Linux Administrator   DS Services of America, Inc. 2300 Windy Ridge Pkwy Suite 600 N Atlanta, GA 

RE: isc-bind-esv Repository - "yum update" doing undesirable things!

2019-05-13 Thread Lightner, Jeffrey
You could look at RHEL's "alternatives" setup to specify paths. "man alternatives" is a good place to read about the command. The RHEL user guides have detail as well. Alternatives is used on RHEL by default for mail (e.g. sendmail or postfix). I've used it to change the default Java

RE: DNS flag day

2019-01-18 Thread Lightner, Jeffrey
On checking I find that any of our domains that use Network Solutions’ Worldnic.com nameservers are reporting failures when checked. For example this result: https://ednscomp.isc.org/ednscomp/e30c6cf0ea Other people online have posted about Network Solutions as they also saw failures. On

RE: Rewrite/Override QTYPE with RPZ

2018-11-09 Thread Lightner, Jeffrey
That wouldn't help you much. Many mail systems these days check not only your MX record but also your PTR record to make sure the IP you came from has a valid (i.e. not generic) reverse lookup. They'll also check things like dkim or spf TXT records. If they don't like what they find

RE: Separate DNS slaves as internal and external

2018-03-22 Thread Lightner, Jeffrey
You can use views for internal and external. Just create a secondary IP on the same NIC you're using as primary on each hosts. Set the transfer hosts for the external view using the primary IP on the NIC and the ones for the internal view on the secondary NICs. You can set ACLs that say

RE: [Question] zone transfer issue with multiple views

2017-12-08 Thread Lightner, Jeffrey
When we did it here we setup separate notify-source and transfer-source within the views on both the master and the slave. view "internal" { match-clients { internaldns; }; notify-source 10.9.9.8.; transfer-source 10.9.9.8; allow-transfer { dnsservers; }; ...then our zones for internal view

RE: Issue with AT IPs?

2017-12-05 Thread Lightner, Jeffrey
I don't disagree with what you say about nameserver diversity but don't feel that is the issue here and is missing the point in my question. I'd already eliminated "lookup" of the DNS servers by going straight to the IP they share. Connections from locations outside our network to that IP port

Issue with AT IPs?

2017-12-05 Thread Lightner, Jeffrey
We're having issues send email to a user @SIDDHAFLOWERS.COM Investigation here shows that the issue we have is querying your name servers (both by name and by IP) are refusing to respond to our name servers. Their name servers: NS1.QUICKFIX8.COM NS2.QUICKFIX8.COM Our name servers:

RE: named and use of resolv.conf? - how to "learn" this

2016-08-02 Thread Lightner, Jeffrey
On the server running BIND if you're trying to resolve addresses with many commands it will use /etc/nsswitch.conf which usually will say to go to "dns" first then to "files" if that doesn't work. The "dns" tells it to use /etc/resolv.conf. Therefore you'd want to add 127.0.0.1 to your list

RE: Questions on how to setup Reverse DNS in bind 9

2016-07-18 Thread Lightner, Jeffrey
I haven't done it with GoDaddy but many providers WILL delegate reverse IPs to you if you request it. Personal editorial comment: Were it me I wouldn't use GoDaddy for anything. I detest GoDaddy because their whole business model seems aimed at forcing you to leap through hoops to do

RE: Questions on bind-chroot

2016-06-13 Thread Lightner, Jeffrey
Is this RHEL5? RHEL6? Something else? On RHEL5 we had bind-chroot running and did all our edits directly in /var/named/chroot/etc for named.cocnf and /var/named/chroot/var/named for zone files. In RHEL7 (which uses systemctl rather than service) they setup special mounting in the