Re: Overwrite A record from DNSSEC protected domain if I am the owner of the domain

2017-04-26 Thread Matus UHLAR - fantomas
like 192.168.0.1, that is only reachable from the LAN this can be done using small resolver in the LAN that resolves the name to internal IP. Should be no problem unless your end-resolvers check DNSSEC -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Unable to slave root zones

2017-04-07 Thread Matus UHLAR - fantomas
zone. did you check on more of them? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Windows found: (R)emov

Re: Unable to build BIND 9.11.0-P3 on RHEL 6.0 64-bit

2017-03-29 Thread Matus UHLAR - fantomas
to avoid this. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fucking windows! Bring Bill Gates! (Southpark the movie

Re: Recognizing remote IP in shared connections

2017-02-28 Thread Matus UHLAR - fantomas
-- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I feel like I'm diagonally parked in a paralle

Re: Enforce EDNS

2017-02-07 Thread Matus UHLAR - fantomas
mber for a while, but retry with edns on after. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Boost your system's speed by 500%

Re: rDNS

2017-01-20 Thread Matus UHLAR - fantomas
  IN   PTR  network.archaxis.net. 81  3600    IN   PTR  alpha.archaxis.net. 82  3600    IN   PTR  bravo.archaxis.net. 87  3600    IN   PTR  broadcast.archaxis.net. What is wrong?  Is this my problem, or with AT? -- Matus UHLAR - fantomas, uh...@fantomas

Re: bind does not resolved all domains (SERVFAIL)

2017-01-13 Thread Matus UHLAR - fantomas
10:06 AM, Matus UHLAR - fantomas wrote: try: dig +trace any phdcomics.com On 13.01.17 10:26, Clément Fevrier wrote: here the result: % dig +trace any phdcomics.com phdcomics.com. 172800 IN NS ns2.speakeasy.net. phdcomics.com. 172800 IN NS ns1

Re: bind does not resolved all domains (SERVFAIL)

2017-01-13 Thread Matus UHLAR - fantomas
+trace any phdcomics.com that should help more than comparing to other nameservers if they can query that domain. Note that the domain has mismatched delegation, according to some DNS checkers. also, the servers have very short TTLs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Matus UHLAR - fantomas
servers as forwarders - without any real need. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Quantum mechanics: The dreams stuff is made

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Matus UHLAR - fantomas
ward only dns server or will there be any problems related caching etc with this conf. On Thu, Nov 24, 2016 at 3:06 PM, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: no, the good configuration is if you do the recursion yourself, without forwarding to google. On 24.11.16 17:10, S

Re: Blocking reverse lookup queries for private ips

2016-11-24 Thread Matus UHLAR - fantomas
ward only dns server or will there be any problems related caching etc with this conf. no, the good configuration is if you do the recursion yourself, without forwarding to google. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adverti

Re: Error while building BIND 9.11 on linux host

2016-11-21 Thread Matus UHLAR - fantomas
penssl make make install just a side note: it's quite funny that some people set system that has 10-years support and start installing things they won't get support for... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adver

Re: Enterprise DNS Architecture - AD and BIND

2016-11-09 Thread Matus UHLAR - fantomas
ath should make better results and forwarding makes the path longer... if you are going the multi-AD way, simply forward from requests from AD to a few BIND caching servers (slaving your internal zones) that will have access to outside. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.f

Re: Enterprise DNS Architecture - AD and BIND

2016-11-09 Thread Matus UHLAR - fantomas
es... that will give you better performance and faster propagation of changes. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Micro$o

Re: forward only recursive server doesn't forward

2016-10-20 Thread Matus UHLAR - fantomas
IN CNAME 97/28 ... 111 IN CNAME 111/28 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. If Barbie is so popular, why

Re: R: Reloading match-clients

2016-10-14 Thread Matus UHLAR - fantomas
dns update for the RPZ zone). On 14/10/16 11:48, Job wrote: is there a way to update/change this section without reloading or with a very-soft reload? Yes. Use "rndc reconfig" instead of "rndc reload". Regards, Anand -- Matus UHLAR - fantomas, uh...@fantomas.sk ; ht

Re: How to request ixfr updates against public ip directly instead of unicast ip in bind

2016-10-12 Thread Matus UHLAR - fantomas
and we have port opened slave to master with public ip. Do we have any option checking for SOA value directly with public ip of master instead of unicast ip. I don't get it. What do you mean by "unicast" and "public" IP? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.

Re: Unspecified error DNS query

2016-10-08 Thread Matus UHLAR - fantomas
in the dig output since other queries do not show TCP mode in their output? responses that are over 512 bytes (maximum packet size without EDNS) must be truncated in UDP mode and thus must be responded in TCP mode. try running: dig +bufsize=4096 outlook.live.com. that shoud avoid TCP...

Re: Multiple A Records - Followup Question

2016-10-03 Thread Matus UHLAR - fantomas
that can't correctly emit the right EHLO for outbound email should remain in the 1990s. I found it problematic, not helpful. It's much safer and easier to have one PTR record with correct fcrdns when sending mail than having multiple DNS records (even with valid fcrdns). -- Matus UHLAR - fantomas, uh

Re: adding zone forwards without restart

2016-09-30 Thread Matus UHLAR - fantomas
"service named restart" on EL6 and "service named-chroot restart" on EL7) works. apparently there's something like that (copying files) in startup scripts or related to puppet installation. tried running without chroot for a while, if it helps? -- Matus UHLAR - fantomas, uh...@

Re: Unable to Load the Zone file

2016-09-27 Thread Matus UHLAR - fantomas
What is the problem here? is there something you don't understand on error message? "NS record '72.31.4.5.' appears to be an address" IP Address can only appear at right side of A record ( for ipv6 addresses). NS records needs domain names on right side. -- Matus UHLAR - fa

Re: root.hind or named.hint file update

2016-09-23 Thread Matus UHLAR - fantomas
uiltin hints file than having outdated hints file. But if someone does care about hints file, it's better to have current version, when the builtin one is older. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this a

Re: R: Minimal responses and speeding up queries

2016-09-23 Thread Matus UHLAR - fantomas
a query. If you turn mimimal-responses on, the required data may not be in the answer. That will result into another query send, which means number of queries increases. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Fwd: Re: adding second zone

2016-09-23 Thread Matus UHLAR - fantomas
1.168.192.in-addr.arpa is on primary zone, if I add second zone I've this error you apparently have 1.168.192.in-addr.arpa defined two times what are you trying to do? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: adding zone forwards without restart

2016-09-23 Thread Matus UHLAR - fantomas
ent. there's "rndc flushtree" command since 9.9, that flushes domain and subdomains when issued. You can use it if needed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chce

Re: Minimal responses and speeding up queries

2016-09-22 Thread Matus UHLAR - fantomas
minimal responses often results into additional queries needed, by definition. If you want to avoid additional queries, turn minimal_responses off. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto a

Re: adding zone forwards without restart

2016-09-22 Thread Matus UHLAR - fantomas
On 21.09.16 14:49, philippe.simo...@swisscom.com wrote: and after a forward add a rndc flush can help too .. not needed unless old forwarders provide invalid data. -Original Message- From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Matus UHLAR - fantomas Sent

Re: forwarder (YES/NO)

2016-09-21 Thread Matus UHLAR - fantomas
: // forwarders { // 8.8.8.8; 8.8.4.4; //} but testing 127.0.0.1, bind keep also 4000/5000ms to resolve a query forwarders { 127.0.0.1; } do you forward to yourself??? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Querying locally on a nameserver - odd behavior

2016-09-21 Thread Matus UHLAR - fantomas
{any;} in BIND config and the above is local on the host (obtained via slaving). The listen-on is set to 'any' on port-53 What am I missing? Why this odd behavior? a firewall probably? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: adding zone forwards without restart

2016-09-21 Thread Matus UHLAR - fantomas
master zones? Did you run named-checkconf as Benny advised? Did you run named-checkzone for the newly added zones? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT ak

Re: forwarder (YES/NO)

2016-09-20 Thread Matus UHLAR - fantomas
with 9.10, leave prefetch on and see... On 20.09.16 15:12, Pol Hallen wrote: I've 9.9.5 version on debian stable :-/ so simply leave BIND running and see if it's better tomorrow... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: forwarder (YES/NO)

2016-09-20 Thread Matus UHLAR - fantomas
difference is that most of those data are probably already cached. How can I replicate same thing? just leave bind running for some time. with 9.10, leave prefetch on and see... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: forwarder (YES/NO)

2016-09-20 Thread Matus UHLAR - fantomas
some time? BIND should cache frequently used data and provide them quickly. when you use google forwarder, the main difference is that most of those data are probably already cached. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail a

Re: replicate a whole master

2016-09-19 Thread Matus UHLAR - fantomas
that means? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fighting for peace is like fucking for virginity

Re: DNS views and zone transfers

2016-09-07 Thread Matus UHLAR - fantomas
- external { zone example.org { }; zone example.com { }; }; -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Christian Scien

Re: Question about dynamic IPv6-PTR-Generation

2016-08-26 Thread Matus UHLAR - fantomas
On 26.08.16 07:34, Tom Tom wrote: I'm searching a way to respond to IPv6-PTR-Queries like the "$GENERATE"-mechanism for IPv4 has done it. why? configuring single IP addresses or taking them from DHCP is easier than creating new useless mechanism. -- Matus UHLAR - fantomas, uh...@f

Re: Slaves or Forwarders?

2016-08-25 Thread Matus UHLAR - fantomas
rver instances (e.g. IPSEC tunnels). On 24.08.16 08:00, Mark Andrews wrote: named only accepts IXFR over TCP. While the protocol supports sending deltas with IXFR/UDP named does not use that part of the protocol. just IXFRs or AXFRs too? Isn't edns over UDP enough in many cases? --

Re: getting not authoritative with some notifies - Solved

2016-08-02 Thread Matus UHLAR - fantomas
often that someone migrates domain off your server. However you can avoid this issue by running either multiple dns servers, bind instances or views, recursive-only on 127.0.0.1 and authoritative on public IP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: getting not authoritative with some notifies - Solved

2016-08-01 Thread Matus UHLAR - fantomas
On Sat, 2016-07-30 at 21:40 +0200, Matus UHLAR - fantomas wrote: or simply wait till customers complain and tell them they should tell you when tthey migrated their zones off. On 31.07.16 18:00, Carl Byington wrote: Which customers will complain? funny that you have answered below

Re: getting not authoritative with some notifies - Solved

2016-07-30 Thread Matus UHLAR - fantomas
On 2016-07-29 08:21, Matus UHLAR - fantomas wrote: On 28.07.16 12:13, Paul A wrote: Now what is everyone using to make sure the zones in named.conf are still pointing to your NS servers? I have a lot of stale DNS zones I want to remove. separate authoritative and recursive servers. bill

Re: getting not authoritative with some notifies - Solved

2016-07-29 Thread Matus UHLAR - fantomas
complain and tell them they should tell you when tthey migrated their zones off. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R)etry

Re: outgoing-traffic

2016-07-27 Thread Matus UHLAR - fantomas
On 27 July 2016 at 15:10, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: however, if no responses will come from his server, it's more likely that the queries will stop. On 27.07.16 15:19, S Carr wrote: If you look at the capture there doesn't appear to be any responses bein

Re: outgoing-traffic

2016-07-27 Thread Matus UHLAR - fantomas
going to repeatedly ask for it and the traffic has already hit your system before ANY queries would be denied. however, if no responses will come from his server, it's more likely that the queries will stop. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning:

Re: Overriding TTL per resource-record on slave

2016-07-26 Thread Matus UHLAR - fantomas
? since all resource records have their own TTL, you can simply give those you want lover TTL than the others. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Overriding TTL per resource-record on slave

2016-07-26 Thread Matus UHLAR - fantomas
is to run a dynamic update (nsupdate) wrapper script to update TTL entries for desired resource-records on our slave. Is there a better way to achieve this? your slave will only forward the update to master. Your description does not make sense, what exactly do you want to achieve? -- Matus

Re: Questions on how to setup Reverse DNS in bind 9

2016-07-21 Thread Matus UHLAR - fantomas
and regenerated the SSL certs, things might have started working. this is your problem. don't generate ssl keys when adding IPs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Questions on how to setup Reverse DNS in bind 9

2016-07-20 Thread Matus UHLAR - fantomas
n but when we get into the new house, I'll change it so the IP address for the second A record points to my server at the house. That way, if one server goes down, people can still connect. It'd be a great opportunity to learn this stuff a bit more I think. good idea. -- Matus UHLAR

Re: Questions on how to setup Reverse DNS in bind 9

2016-07-19 Thread Matus UHLAR - fantomas
dn't setup another A name for franklin? Thanks and sorry for all the questions. I know these probably aren't really bind related questions anymore. Thanks! once more: jetbbs.com IS NOT franklin.jetbbs.com ! FYI currently they both only contain 104.238.117.105 -- Matus UHLAR - fantomas, uh...@f

Re: Query on the Order in which RR are answered by Bind of Order/preference are Same

2016-07-18 Thread Matus UHLAR - fantomas
nly for your bind instance - any other nameserver can change the order. why don't you use higher order if you want to have them in order? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adr

Re: Resolving issue on specific domain

2016-07-16 Thread Matus UHLAR - fantomas
On 15.07.16 14:05, Daniel Dawalibi wrote: Dig domainname -> Server failed On Jul 15, 2016, at 8:48 AM, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: please show us output of it. when 127.0.0.1 is first in /etc/resolv.conf, dig should contact localhost first, and the resu

Re: Resolving issue on specific domain

2016-07-15 Thread Matus UHLAR - fantomas
ed Dig domainame localhost -> Resolving properly and, please remove the parts that are not important, don't sent useless crap to mailing list. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie

Re: Resolving issue on specific domain

2016-07-15 Thread Matus UHLAR - fantomas
On 15.07.16 12:05, Daniel Dawalibi wrote: To: 'Matus UHLAR - fantomas' <uh...@fantomas.sk>, bind-users@lists.isc.org please avoid personal replies. use list-reply whenever possible. I already did it as per below output of resolv.conf but problem persists. do you want to say, even

Re: Sending extra info in bind dns query packet

2016-07-15 Thread Matus UHLAR - fantomas
here other way I can send this extra info through the bind dns query packet? it's highly dependent on what exactly you want to achieve. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto ad

Re: Resolving issue on specific domain

2016-07-15 Thread Matus UHLAR - fantomas
, 194.126.10.18 does not know the "domainname" you must add localhost to resolv.conf as first nameserver to get answers from it by default. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: Unable to understand why a different A record response being sent by bind

2016-06-20 Thread Matus UHLAR - fantomas
test1.com for examples... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about c

Re: Append a Hard-coded Text Tuple into Additional Section of "dig" Feature

2016-06-17 Thread Matus UHLAR - fantomas
ome information that I want to include" 1. there's no point in adding TXT rrs to additional section, they do not belong there 2. why at all do you want to put them there? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adverti

Re: Ability to limit memory usage for zones on an authoritative server.

2016-06-05 Thread Matus UHLAR - fantomas
is not an issue) and didn't want to do the work of changing some standard zone lists and data we use. what kind of zones are they? why do you load them if you don't want to use them? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Strange intermittent resolution

2016-05-27 Thread Matus UHLAR - fantomas
. amlinuxmedia.com. 86400 IN NS ns2.host-for.com. got it? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One OS to rule them all

Re: resolution problem

2016-05-25 Thread Matus UHLAR - fantomas
In article <mailman.812.1463666011.73610.bind-us...@lists.isc.org>, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: often a problem of invalid NS delegation, or bad TTL (A record for a server expires before NS record). On 19.05.16 15:31, Sam Wilson wrote: Glue A records for the

Re: Forward zone not working

2016-05-21 Thread Matus UHLAR - fantomas
tocol just to provide generic DNS records for each leaf (home) network... yes, we need something new for IPv6. But not for creating bulks of useless generic records. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to th

Re: Forward zone not working

2016-05-21 Thread Matus UHLAR - fantomas
uld give a shorthand. I have no idea how will ordinary DNS in ipv6 look like, but I doubt it will look like this... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOS

Re: resolution problem

2016-05-19 Thread Matus UHLAR - fantomas
a.colostate.edu. >dpc.cira.colostate.edu. 3600IN A 129.82.109.62 >;; Received 83 bytes from 129.82.103.121#53(dns1.colostate.edu) in 36 ms In article <mailman.812.1463666011.73610.bind-us...@lists.isc.org>, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: often a problem of

Re: resolution problem

2016-05-19 Thread Matus UHLAR - fantomas
.121#53(dns1.colostate.edu) in 36 ms often a problem of invalid NS delegation, or bad TTL (A record for a server expires before NS record). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto

Re: Logging question about message 'update-security: error: client update denied'

2016-05-17 Thread Matus UHLAR - fantomas
in DNS (it's on by default in netowrk settings). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "They say when you play that M$ CD backw

Re: i have a question ?

2016-04-14 Thread Matus UHLAR - fantomas
on no ), i found forwarding required recursion. You must turn recursion on (and allos it for your IPs) to do the forwarding. Note that in most cases it's useless to do forwarding if your bind server has connectivity and can do the lookups itself. -- Matus UHLAR - fantomas, uh...@fantomas

Re: multi zone forward ?

2016-04-02 Thread Matus UHLAR - fantomas
e view where clients belong and forward everything... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. LSD will make your ECS screen display

Re: about NS server authorize

2016-03-21 Thread Matus UHLAR - fantomas
nameserver not authorized. contact your registrar about this issue. thisa is not a bind problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: Multiple A records and reverse DNS

2016-03-19 Thread Matus UHLAR - fantomas
, without any valid reason. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The early bird may get the worm, but the second mouse gets

Re: what does "max-ncache-ttl 0;" mean?

2016-03-02 Thread Matus UHLAR - fantomas
s zero, so in effect it would disable negative cacheing. which means, DON'T DO THAT. anyone searching for nonexisting DNS names (e.g. because of a misconfiguration) could easily DoS your server. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive

Re: Intermittent NXDOMAIN for a name we are forwarding

2016-02-22 Thread Matus UHLAR - fantomas
now.. doesn't the log also contain info where did that message come from? Our current work around is to restart named (which cache) or we could do a 'rndc flush'. "rndc flushname myname.mydomain.com" should be enough - not needed to flush whole cache. -- Matus UHLAR - fa

Re: Intermittent NXDOMAIN for a name we are forwarding

2016-02-20 Thread Matus UHLAR - fantomas
in "Unassociated entries" when the problem happens. anything more isble in the cache? last time I have encountered this error, it was problematic Cisco DNS load balancer, responding NXDOMAIN to a PTR (and possibly other) type queries, while standard types returned proper answer. -- M

Re: has no address records (A or AAAA)

2016-01-28 Thread Matus UHLAR - fantomas
s.org" in file "192.168.99.zone" that contains the reverse zone, not zone cts.org. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek r

Re: Allow-Query=any

2016-01-07 Thread Matus UHLAR - fantomas
o, instead of providing type "ANY" you want people to flood your server with multiple queries for type? if you have problems, response rate limiting should be better solution. ...I received spam from comnpany with NS hosted at cloudflare that refuses ANY query. I am considering ignoring such doma

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
Hello, On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks,  On 27.12.15 18:07, Matus UHLAR - fantomas wrote: I'd choose logging at kernel level in iptables firewall. ULOG

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks,  I'd choose logging at kernel level in iptables firewall. ULOG and ulogd can log to libpcap format. -- Matus UHLAR

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks, Am 27.12.2015 um 18:07 schrieb Matus UHLAR - fantomas: I'd choose logging at kernel level in iptables firewall. ULOG

Re: Multiple logs

2015-12-27 Thread Matus UHLAR - fantomas
On 26.12.15 20:30, kev wrote: I am using bind9 with ubuntu 14.04. I was wondering how to log by indivudual IP. Ive googled it but didnt find what i was looking for.Thanks, Am 27.12.2015 um 18:07 schrieb Matus UHLAR - fantomas: I'd choose logging at kernel level in iptables firewall. ULOG

Re: Why two lookups for a CNAME?

2015-10-23 Thread Matus UHLAR - fantomas
Am 22.10.2015 um 14:01 schrieb Matus UHLAR - fantomas: I wonder if it's not enough to verify that the first response was received from proper server. Since play.l.google.com is a subdomain of play.google.com, the lookup would go throuth google.com nameservers again... when servers

Re: Why two lookups for a CNAME?

2015-10-22 Thread Matus UHLAR - fantomas
ample too... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Depression is merely anger without e

Re: How does a Client Verify if the DNS server is Alive or down

2015-10-20 Thread Matus UHLAR - fantomas
it periodically send any messages to the server. What Kind of messages are required by the client to be sent towards server to determine if the DNS IP is reachable or not? what is your problem? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: dname reverse delegation

2015-10-14 Thread Matus UHLAR - fantomas
ave yourself trouble by doing so? If not, you should probably reconsider. [...] Don't be distracted by RFC2317. It describes the trickery you need when you're dealing with a longer prefix (fewer addresses) than a /24. If you have "a few /24", you can deal with them without needing

Re: FW: SRV Request to DNS

2015-10-12 Thread Matus UHLAR - fantomas
care themselves. please provide more detailesd question, or search archives if it hasn't been answered already. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Options for non-recursive servers

2015-09-23 Thread Matus UHLAR - fantomas
in some cases receive multiple requests that could be avoided without this. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give

Re: Multiple A and PTR and the "main" ones?

2015-09-11 Thread Matus UHLAR - fantomas
. Is it a bad practice? it is a bad practice and leads exactly to the problems you describe when the other side tries to verify A/PTR matching because there is just no ordering like there is also no rodering having multiple A records for the same name with different IP's agreed. -- Matus UHLAR

Re: questions about DNS notify

2015-09-10 Thread Matus UHLAR - fantomas
will master query from, to get the IP addresses for those slaves? it will run standard resolution procedure - try lookup from root, or configured forwarders, unless having nsbeta.info configured locally. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Solved - Re: A tale of two nameservers - resolution problems

2015-09-03 Thread Matus UHLAR - fantomas
, although it doesn't fix the issue with boards without RTC. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. We are but packets in the Intern

Re: DNS Negative Caching

2015-08-28 Thread Matus UHLAR - fantomas
slaves see the ttl within each record... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One OS to rule them all, One OS to find them, One

Re: [OT] Re: configuration error in lists.isc.org

2015-08-07 Thread Matus UHLAR - fantomas
that broke this behaviour. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One World. One Web. One Program. - Microsoft promotional advertisement

Re: [OT] Re: configuration error in lists.isc.org

2015-08-07 Thread Matus UHLAR - fantomas
Am 07.08.2015 um 08:29 schrieb Matus UHLAR - fantomas: SPF must only check envelope address, not header From: address - it was never designed to do the latter. On 07.08.15 17:23, Heiko Richter wrote: Correction: - All implementations of SPF always check 2 addresses: - Envelope

Re: How to properly update chroot-bind

2015-07-28 Thread Matus UHLAR - fantomas
~]# uname -a Linux centos-dns1.virtual.com.ar 2.6.32-504.23.4.el6.x86_64 #1 SMP Tue Jun 9 20:57:37 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux Doing yum update bind-chroot is not the way. This is not a production server yet but it will be soon. yum update bind should do that. -- Matus UHLAR - fantomas

Re: How to properly update chroot-bind

2015-07-28 Thread Matus UHLAR - fantomas
Am 28.07.2015 um 10:56 schrieb Matus UHLAR - fantomas: but you *never ever* should only update specific packages on a RHEL/CentOS system because that is *not supported and tested* at all No? What are dependencies for, then? Or don't yum/RPM support them in the way debian does? (that is why

Re: setting and monitoring dns cache master / slave pair

2015-07-07 Thread Matus UHLAR - fantomas
On 06.07.15 16:39, Leandro wrote: 3)Does it have any drawbacks no declaring any zone file in the long term? you should declare at least RFC 1918/3330/5735 reverse zones, to prevent from forwarding queries to root servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: file descriptor exceeds limit

2015-06-18 Thread Matus UHLAR - fantomas
to increased number of TCP queries which slows down resolution ... By the way, the resolvers are running RHEL 6.x. precise BIND version would help a bit more... seems RH6.6 contains 9.8.2 but that may be different for older RH6 versions. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: Automatic . NS queries from BIND

2015-06-17 Thread Matus UHLAR - fantomas
file changes whenever new BIND release gets out, while the bungled hints file may be updated by packagers or manually. I'd say that the bundled hints file is likely to be newer than the hard-coded one. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Getting an error on a simple DNS configuration

2015-06-03 Thread Matus UHLAR - fantomas
-- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Emacs is a complicated operating system without good text editor

Re: Suppress log entry...

2015-04-14 Thread Matus UHLAR - fantomas
...@gmail.com wrote: in other words: if you everytime you change the config hard restart named instead a reload you are doing it terrible wrong with a ton of bad side effects -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: rndc flushname not working

2015-04-09 Thread Matus UHLAR - fantomas
the entire cache to get resolution working properly on that domain again. this indicates that any of NS records the domain points to returns NXDOMAIN for the domain. hard to tell without more info, but some web DNS checkers are able to trace this kind of issues... -- Matus UHLAR - fantomas, uh

Re: bind-users Digest, Vol 2083, Issue 1

2015-04-07 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Where do you want to go to die? [Microsoft] ___ Please

Re: NAMED try to solve domain from old authoritative server

2015-04-02 Thread Matus UHLAR - fantomas
, the problem occur again. Does anyone ever face this problem? such problems appear when people put incorrect NS records to zone files. Note that not only parent zone must have proper NS (glue) records to child zones, but the child zones must have them too. -- Matus UHLAR - fantomas, uh

Re: BIND not loading into memory on first transfer

2015-03-27 Thread Matus UHLAR - fantomas
denied writing the tmp-x file that happens prior to writing it out to the zone file itself. and how do hey differ from the second transfer? If they don't itmay be a bug (or a bug) in named that it behaves differently after first and other transfers... -- Matus UHLAR - fantomas, uh...@fantomas.sk

<    1   2   3   4   5   6   7   8   9   10   >