Re: "not subdomain of zone {XXXX} -- invalid response" errors found in named.run log

2021-01-13 Thread Mark Andrews
> On 7 Jan 2021, at 00:57, 同屋 <39223...@qq.com> wrote: > > Actually, the background is a little bit complicated. In short, the topo is > as belows. dns1 were swapped by a new one (say dns1*), then the issue > happened. After that, we dropped all the request from dns1*, then the > issue w

RE: Getting "query failed (REFUSED) for ./IN/ANY"

2021-01-13 Thread Richard T.A. Neal
Matus UHLAR - fantomas wrote: > fail2ban should help not to see those messages I expect there are probably only two people on the planet running BIND on Windows: me, and the ISC Developer responsible for building the Windows binaries 😊 As part of a larger project I've been developing a series

Re: Getting "query failed (REFUSED) for ./IN/ANY"

2021-01-13 Thread Alessandro Vesely
On Wed 13/Jan/2021 14:31:58 +0100 John Kristoff wrote: Some may be sourced from a security/research survey project, but some sources performing this may be for more nefarious purposes - building a list of open resolvers that will answer for the purposes of maintaining an amplication/reflection hi

Re: Getting "query failed (REFUSED) for ./IN/ANY"

2021-01-13 Thread tale via bind-users
> >Are the queries refused because of the dot (.)? In the query log, I also > > found some 28 IN ANY queries from 7 IPs for xxx.at.fragolina.it, which > > probably got away with a NXDOMAIN. > > no. the dot is just the root domain. Correct that . is the root domain, but I'd say the answer is a qua

Re: Getting "query failed (REFUSED) for ./IN/ANY"

2021-01-13 Thread John Kristoff
On Wed, 13 Jan 2021 10:21:19 +0100 Alessandro Vesely wrote: > Yesterday I got 42639 of those, from 41 different IPs, the most frequent > clients looking like so: > 821-north:~$ sed -rn 's/^.{15} 30 north named[^:]*: client @0x[0-91-f]* > ([0-9.]*)#[0-9]* ...: view external: query failed .REFUSE

Re: Getting "query failed (REFUSED) for ./IN/ANY"

2021-01-13 Thread Alessandro Vesely
On Wed 13/Jan/2021 11:03:01 +0100 Matus UHLAR - fantomas wrote: On 13.01.21 10:21, Alessandro Vesely wrote: Are the queries refused because of the dot (.)?  In the query log, I also found some 28 IN ANY queries from 7 IPs for xxx.at.fragolina.it, which probably got away with a NXDOMAIN. no. th

Re: Getting "query failed (REFUSED) for ./IN/ANY"

2021-01-13 Thread Matus UHLAR - fantomas
On 13.01.21 10:21, Alessandro Vesely wrote: I'm getting lots of log lines like the following: Jan 12 04:35:18 30 north named[22233]: client @0x7fe0fc2a3b80 74.74.74.8#24048 (.): view external: query failed (REFUSED) for ./IN/ANY at ../../../bin/named/query.c:7144 Jan 12 04:35:18 30 north named

Getting "query failed (REFUSED) for ./IN/ANY"

2021-01-13 Thread Alessandro Vesely
Hi, I'm getting lots of log lines like the following: Jan 12 04:35:18 30 north named[22233]: client @0x7fe0fc2a3b80 74.74.74.8#24048 (.): view external: query failed (REFUSED) for ./IN/ANY at ../../../bin/named/query.c:7144 Jan 12 04:35:18 30 north named[22233]: client @0x7fe0fc2784d0 74.74.74