Re: Bind 9 not responding to queries

2020-04-12 Thread sir izake
Ok Stephane There's no firewall or IPS in front of the DNS. Only the Centos firewall policy permitting dns traffic. Sure, I will take the tcpdump and revert Thanks & Best Regards Isaac On Sun, 12 Apr 2020, 3:48 pm Stephane Bortzmeyer, wrote: > On Sun, Apr 12, 2020 at 01:41:52AM +, >

Re: Bind 9 not responding to queries

2020-04-12 Thread Stephane Bortzmeyer
On Sun, Apr 12, 2020 at 01:41:52AM +, sir izake wrote a message of 153 lines which said: > At specific times of day bind fails to respond to queries even > though service is shown to run (configured to respond to my network > IPs, this works fine till this time when service fails to

RE: Bind 9 not responding to queries

2020-04-12 Thread John W. Blue
Sir Izake, Any network troubleshooting starts with finding out what is being placed on the wire. In your particular example it sounds like you need to validate if this Cent box is seeing a SYN flood. You do this by using tcpdump. Assuming you only have one ethernet adapter (which by

Bind 9 not responding to queries

2020-04-12 Thread sir izake
Hi Support I have installed BIND 9.11.4-P2-RedHat-9.11.4-26.P2.el8 on CentOS Linux release 8.1.1911. I have configured bind as a recursive server for my network. At specific times of day bind fails to respond to queries even though service is shown to run (configured to respond to my network

Re: DHCPD - BIND DDNS: dnssec-keygen hmac-md5 removed

2020-04-12 Thread Mark Andrews
Use tsig-keygen. -- Mark Andrews > On 11 Apr 2020, at 09:52, moo can via bind-users > wrote: > >  > Hello, > > For educational purpose I need to setup an DDNS between DCHPD and BIND. > > Everywhere, debian, zytrax, freeipa, veritas ... use dnssec-keygen. > Zytrax: > dnssec-keygen -a

Is it possible to do In-line Signing for local root zone

2020-04-12 Thread Mundile
I have local (private) root domain domainX.example and subdomains : subdomainY.domainX.example and subdomainZ.domainX.example. I can do chain of trust if all zones are In-line signed zone "domainX.example" { type master; file "named.domainX.example"; key-directory