Re: Bind to INADDR_ANY

2012-01-10 Thread Phil Mayers
On 01/10/2012 01:12 AM, Bostjan Skufca wrote: Hi everyone, is binding to all interfaces at once already supported in bind9? I know named binds to each at-the-moment-available IP address but in HA environment with virtual interfaces a rndc reload is necessary for named to pick up a new

Re: Is bind support conditionally resolution?

2012-01-10 Thread Peter Andreev
2012/1/10 Drunkard Zhang gongfan...@gmail.com I am designing a big deploy system, which will implement via DNS. The demond is misc, one of them is conditionally resolve, which means that if one CDN node near unavailable, or latency increased significantly, no matter why, I want bind to give

Re: Is bind support conditionally resolution?

2012-01-10 Thread Giles Coochey
On Tue, January 10, 2012 08:04, Drunkard Zhang wrote: I am designing a big deploy system, which will implement via DNS. The demond is misc, one of them is conditionally resolve, which means that if one CDN node near unavailable, or latency increased significantly, no matter why, I want bind to

Re: RFC 6303 vs. BIND: NS ... has no address records (A or AAAA)

2012-01-10 Thread Tony Finch
Irwin Tillman ir...@princeton.edu wrote: What's the recommended approach? My empty zone is: @ SOA localhost. root.localhost. 1 1h 1000 1w 1h NSlocalhost. I also have a localhost. zone (RFC 2606) which is: @ SOA localhost. root.localhost. 1 1h 1000 1w 1h NSlocalhost. A

Re: Bind to INADDR_ANY

2012-01-10 Thread michoski
On 1/9/12 5:12 PM, Bostjan Skufca bost...@a2o.si wrote: is binding to all interfaces at once already supported in bind9? I know named binds to each at-the-moment-available IP address but in HA environment with virtual interfaces a rndc reload is necessary for named to pick up a new interface,

Re: Help to identify Microsoft DNS version

2012-01-10 Thread michoski
On 1/9/12 11:38 PM, babu dheen babudh...@yahoo.co.in wrote: Can anyone help me how to find bind microsoft DNS software version using dig or nslookup command remotely? There are various fingerprinting methods you can use, with widely varying degrees of accuracy, but the most polite way is to

Configuring Bind on a dynamic ip, DDNS.

2012-01-10 Thread Eduardo Bonsi
Hello all. I had to cancel my static external ip because my ISP wants too much money for it and it did not justify to pay for that kind of price since we are a small firm. I tried to negotiate but we all know how hard is to convince a corporate monopoly executive to get down from the clouds to

Re: Help to identify Microsoft DNS version

2012-01-10 Thread Warren Kumari
On Jan 10, 2012, at 3:00 PM, michoski wrote: On 1/9/12 11:38 PM, babu dheen babudh...@yahoo.co.in wrote: Can anyone help me how to find bind microsoft DNS software version using dig or nslookup command remotely? There are various fingerprinting methods you can use, with widely varying

Re: Bind to INADDR_ANY

2012-01-10 Thread Mark K. Pettit
There are some caveats to trying to use interface-interval to pick up new IPs. If your BIND drops privileges (e.g., by using the -u command-line option to named), you might have a problem getting BIND to bind() to the new IP addresses. For example, on FreeBSD if you use -u to drop privileges,

Re: Bind to INADDR_ANY

2012-01-10 Thread Doug Barton
On 01/10/2012 17:34, Mark K. Pettit wrote: There are some caveats to trying to use interface-interval to pick up new IPs. If your BIND drops privileges (e.g., by using the -u command-line option to named), you might have a problem getting BIND to bind() to the new IP addresses. For

Re: Bind to INADDR_ANY

2012-01-10 Thread Doug Barton
On 01/10/2012 18:38, Mark K. Pettit wrote: On Jan 10, 2012, at 5:53 PM, Doug Barton wrote: On 01/10/2012 17:34, Mark K. Pettit wrote: In my environment (FreeBSD) we've worked around this problem (just recently, in fact), and I can provide more details if there's any interest. well I'm

Re: Bind to INADDR_ANY

2012-01-10 Thread Mark K. Pettit
On Jan 10, 2012, at 5:53 PM, Doug Barton wrote: On 01/10/2012 17:34, Mark K. Pettit wrote: In my environment (FreeBSD) we've worked around this problem (just recently, in fact), and I can provide more details if there's any interest. well I'm definitely interested. :) The short answer is

Re: huge count of DNS deny hits

2012-01-10 Thread babu dheen
Hi,   I enabled the logs in DNS server and i found  below lines from this client continiously..   1/10/2012 9:14:30 AM 0FDC PACKET  05B489B0 UDP Snd Client IP    1f23   Q [0005 A D   NOERROR] TXT    (7)version(4)bind(0) 1/10/2012 9:14:30 AM 0FDC PACKET  07342360 UDP Rcv Client IP 

Re: Bind to INADDR_ANY

2012-01-10 Thread Mark Andrews
In message 4f0cebb5.3040...@dougbarton.us, Doug Barton writes: On 01/10/2012 17:34, Mark K. Pettit wrote: There are some caveats to trying to use interface-interval to pick up new IPs. If your BIND drops privileges (e.g., by using the -u command-line op tion to named), you might have a

DNSSEC authentication and ad parameter

2012-01-10 Thread Gaurav kansal
Dear All, I had purchased a new domain especially for DNSSEC testing. But when I ask my registry to insert my DS keys in .in zone file, I got the answer that .in is still not ready for this although .in is signed. I tried to authenticate my domain through ISC dlv. I upload my DS key

Re: huge count of DNS deny hits

2012-01-10 Thread Fajar A. Nugraha
On Wed, Jan 11, 2012 at 12:11 PM, babu dheen babudh...@yahoo.co.in wrote: Hi, I enabled the logs in DNS server and i found  below lines from this client continiously.. 1/10/2012 9:14:30 AM 0FDC PACKET  05B489B0 UDP Snd Client IP    1f23   Q [0005 A D   NOERROR] TXT   

Re: huge count of DNS deny hits

2012-01-10 Thread babu dheen
Dear Fajar,    Below logs taken from Internal DNS server running in Microsoft DNS. I checked with client AV status, everything is fine( system is up to date with DAT from Mcafee AV and no threat found in the complete scan output).   But really no idea.. why it happens..  Client is pointed to use

Re: DNSSEC authentication and ad parameter

2012-01-10 Thread Mark Elkins
It is working. -- $ dig test.nknsec.in +dnssec ; DiG 9.8.1 test.nknsec.in +dnssec ;; global options: +cmd ;; Got answer: ;; -HEADER- opcode: QUERY, status: NOERROR, id: 4578 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 2, ADDITIONAL: 1 ;; OPT

RE: DNSSEC authentication and ad parameter

2012-01-10 Thread Marc Lampo
Hello, The authoritative NS for nknsec.in. *does* give answers with corresponding RRSIG’s ! $ dig @ns1.nknsec.in. test.nknsec.in. +dnssec +short 10.1.27.25 A 5 3 360 20120204072952 20120105072952 16755 test.nknsec.in. DcLPb3hVDqal64UQe3Vk4NjbMRwSSWHNy4r/Bk42M2WQLZYBt9p7NpIT