Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Dmitri Tarkhov
Well, it's Ok with that. I indeed am the owner of small reverse zone 255-241.z.y.x.in-addr.arpa IN { type master; named with accordance with rfc2317 CNAME trick and can edit it. The changes are transferred one way to the ISP side and make part of their zone z.y.x.in-addr.arpa. So my changes are

Re: Signed zone does not get updated 'receive_secure_serial: not exact'

2012-12-27 Thread Thomas Leuxner
Am 26.12.2012 um 23:31 schrieb Mark Andrews ma...@isc.org: * the record to be removed was not there * the record to be aded was already there This means that the two versions of the zone have become unsyncronized. I did some more tests with another zone. Not sure BIND works as intended

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Peter Andreev
Forwarding does not work without recursion enabled. There is a few ways to solve the problem: 1. Using views; 2. Using another dns resolver (for example Unbound); 3. Downloading the zone via script (bad idea from any point); 4. Do not bother where your resolver get authoritative data (I'd

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Dmitri Tarkhov
Hi, thanks a lot for the information. Contains key reason and sounds interesting. 1. Do you mean I can isolate zone z.y.x.in-addr.arpa into a separate view where recursion is enabled but all other zones are excluded? If so, it's very promising. 2. Sorry, Unbound - is it just another dns

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Peter Andreev
2012/12/27 Dmitri Tarkhov tark...@dionaholding.ru: Hi, thanks a lot for the information. Contains key reason and sounds interesting. 1. Do you mean I can isolate zone z.y.x.in-addr.arpa into a separate view where recursion is enabled but all other zones are excluded? If so, it's very

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Dmitri Tarkhov
Ok, thank you, I'll try views first of all. And I need some further clarification about this: I just meant that fencing your resolver without really good reasons is a bad idea. By fencing your resolver do you mean converting a dns server into only a source of information from its master

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Peter Andreev
2012/12/27 Dmitri Tarkhov tark...@dionaholding.ru: Ok, thank you, I'll try views first of all. And I need some further clarification about this: I just meant that fencing your resolver without really good reasons is a bad idea. By fencing your resolver do you mean converting a dns

difference between default views in named_statistics.txt

2012-12-27 Thread benjamin fernandis
Hi, We are using bind as a recursive dns server in our college. It is working fine. Now we need to make a report regarding QPS, NXDOMAIN, FORMAT ERROR, Server Failure, Name Error, Not Implemented, Refused queries comes to our recursive DNS SERVER. For this we use named_statistics file which

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Mark Andrews
In message 50dc2b79.1040...@dionaholding.ru, Dmitri Tarkhov writes: Well, it's Ok with that. I indeed am the owner of small reverse zone 255-241.z.y.x.in-addr.arpa IN { type master; named with accordance with rfc2317 CNAME trick and can edit it. The changes are transferred one way to the ISP

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Doug Barton
On 12/27/2012 11:18 AM, Mark Andrews wrote: zone 241.Z.X.Y.IN-ADDR.ARPA { type master; file 241.Z.X.Y.IN-ADDR.ARPA; }; That's great locally, but it doesn't match the 2317 delegation from the upstream, and usually it's not possible to change what they send you. Or are you

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Mark Andrews
In message 50dcd454.2070...@dougbarton.us, Doug Barton writes: On 12/27/2012 11:18 AM, Mark Andrews wrote: zone 241.Z.X.Y.IN-ADDR.ARPA { type master; file 241.Z.X.Y.IN-ADDR.ARPA; }; That's great locally, but it doesn't match the 2317 delegation from the upstream, and usually

Re: difference between default views in named_statistics.txt

2012-12-27 Thread Alan Clegg
On Dec 27, 2012, at 1:05 PM, benjamin fernandis benjo11...@gmail.com wrote: cat /var/named/chroot/var/named/data/named_stats.txt While this may present what you want, I think you may be happier parsing the Statistics Channel...

Re: difference between default views in named_statistics.txt

2012-12-27 Thread benjamin fernandis
Hi Alan, Thanks for your kind response. I enabled statistics channel and in that i can see Resolver Statistics for View _default and Resolver Statistics for View _bind what is the difference between these two views which also same in named_Statistics file. BR Ben On Fri, Dec 28, 2012 at

Re: reverse zone of type forward when /28 subnet

2012-12-27 Thread Dmitri Tarkhov
Hi, all, thank you very much for discussion. It was interesting and very useful. You can pretty well imagine that I am not much dns involved, I am rather unix and unix HW guy. Unfortunately I saw dns cache poisoning attack and although it could be provoked by side effects it's better to get rid