Re: Not receiving "Fixed/Ordered" query response

2019-01-25 Thread Matus UHLAR - fantomas
es not support "fixed" ordering by default. Fixed ordering can be enabled at compile time by specifying "--enable-fixed-rrset" on the "configure" command line. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail ad

Re: conflicting subdomain delegation

2018-11-16 Thread Matus UHLAR - fantomas
dns-55.co.uk. c.b.jilapps.com.172800 IN NS ns-33.awsdns-04.com. c.b.jilapps.com.172800 IN NS ns-540.awsdns-03.net. servers for c.b.jilapps.com send this, servers for jilapps.com send referrals to c.b.jilapps.com servers -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http:

Re: DNS Query from different Subnet

2018-11-15 Thread Matus UHLAR - fantomas
216 this is not possible with BIND, you must define zhole zone. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do you wa

Re: conflicting subdomain delegation

2018-11-13 Thread Matus UHLAR - fantomas
he b.a.com is delegated, no subdomains of it should appear in a.com zone. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is

Re: Method of writing zone files

2018-11-13 Thread Matus UHLAR - fantomas
can cause all journals to be synced and files saved. You can call this before backup and call rndc thaw after. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT a

Re: forwarder selection logic by bind9

2018-11-11 Thread Matus UHLAR - fantomas
ks the other server(s) to see if situation has changed. BIND does not differ between servers as primary and secondary. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVA

Re: concurrent-session

2018-11-04 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Despite the cost of living, have you noticed how popular it remains

Re: forward zone

2018-10-27 Thread Matus UHLAR - fantomas
s because it is not "trusted" As you can't have "allow-query" in a zone of type "forward", I don't find any nice solution. Le 26/10/2018 à 09:21, Matus UHLAR - fantomas via bind-users a écrit : You can and you also need to add allow-query for it.  However,

Re: Enforcing minimum TTL...

2018-10-26 Thread Matus UHLAR - fantomas
risky, and forcing minimum TTL is apparently not way to work around. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. REALITY.SYS corrupted

Re: forward zone

2018-10-26 Thread Matus UHLAR - fantomas via bind-users
from outside to access forward zone? can't you slave it instead? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTA

Re: resolve - send query via specific network device

2018-10-24 Thread Matus UHLAR - fantomas
/routing-tables.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. There's a long-standing bug relating to the x86 architecture that allo

Re: unable to resolve evisa.dgdi.ga FQDN

2018-10-09 Thread Matus UHLAR - fantomas
francedns.com. ns2.francedns.com and ns3.francedns.com return SERVFAIL. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. - Have you got anything wit

Re: NTP through DNS?

2018-09-25 Thread Matus UHLAR - fantomas
10:00, Danny Mayer wrote: In your domain file add entries like this: this is called local configuration. Simple enough? No. It requires local configuration of NTP server. in that case, DNS-side solution is useless. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: Beginner - Bind - Bad dotted quad

2018-09-24 Thread Matus UHLAR - fantomas
NS x200.fin.local. @ IN A 192.168.1.159 x200 IN A 192.168.1.159 www IN A 192.168.1.159 pfsense IN A 192.168.1.1 hp4000 IN A 192.168.1.12 there's apparently invalid space character on the line above. nstation10 IN A 192.168.1.104 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.s

Re: NTP through DNS?

2018-09-22 Thread Matus UHLAR - fantomas
tion. There is no autoconfiguration we know of, unless DHCP that was reported often not to work. using either CNAME or SRV records won't change the fact that ntp server does not autoconfigure itself. Neither of them also changes the fact that the NTP configuration is not related to domain, bu

Re: load balancing

2018-09-19 Thread Matus UHLAR - fantomas
# 5 is sufficiently undefined that it cannot really be answered :-) What *exactly* is the question / scenario you are asking? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Upgrade help with Bind 9.12

2018-09-12 Thread Matus UHLAR - fantomas
in ubuntu. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Honk if you love peace and quiet. _

Re: Frequent timeout

2018-09-07 Thread Matus UHLAR - fantomas
safer then. Note that the IP was seen in packet capture you have published, not needed to hide it now. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rekl

Re: about the effect of installing with "--without-openssl"

2018-08-26 Thread Matus UHLAR - fantomas
sl (if it exists somewhere) and if there are more than DNSSEC,TSIG and DNS COOKIE mentioned before. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: how two dns bind master sync?

2018-08-22 Thread Matus UHLAR - fantomas
be DNS slave to multiple AD servers. The AD servers contain the data, but serial numbers are unrealiable in this case. I'm afraid the same would apply for your application. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adverti

Re: bind 9.10.6.1 vs 9.10.6

2018-08-21 Thread Matus UHLAR - fantomas
Notes.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Christian Science Programming: "L

Re: [SOLVED] My Exchange server is now able to send email to httpd.apache.org domain after I added SPF TXT record to my DNS server

2018-08-14 Thread Matus UHLAR - fantomas
I need to configure DKIM as well? I have no idea what is DKIM. Please help me to troubleshoot email delivery failure for the freebsd.org domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: Queries regarding forwarders

2018-08-08 Thread Matus UHLAR - fantomas
. ideally you would not use forwarder on BIND, unless you really must. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. If Barbie is so popular

Re: Creating CNAME Resource Records (RR) to Redirect Readers to My Wordpress and Blogspot Blogs Don't Work

2018-08-08 Thread Matus UHLAR - fantomas
HTTP redirect to example.wordpress.com. CNAME does not cause HTTP redirects and no HTTP server I know parses CNAME just to know which site you mean. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: Removing an NS server

2018-08-08 Thread Matus UHLAR - fantomas
asr for "expire" seconds in those zones. the expire is (or should be) usually a week or two. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklam

Re: Reverse DNS record for my webhost

2018-08-07 Thread Matus UHLAR - fantomas
ly set it. I found the following response to someone's question on the *Net*: are you sure you need to search for answers on the net, instead of asking your ISP? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addre

Re: Dropping queries from some well-known ports

2018-08-03 Thread Matus UHLAR - fantomas
port descriptions self-explaining enough? what is the point of this question at all? services are not supposed to bind those low ports, and if anyone wants to do that, they should be aware of possible isss they create. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: named tcp dos?

2018-08-03 Thread Matus UHLAR - fantomas
On 03.08.18 12:10, Tony Finch wrote: > I have a few config options which can affect TCP usage. These two should > reduce it: > >minimal-responses yes; >minimal-any yes; Matus UHLAR - fantomas wrote: I don't think so. minimal-responses only skip unnecessary info,

Re: named tcp dos?

2018-08-03 Thread Matus UHLAR - fantomas
lue because of problematic L3 switch in front of our DNS servers long ago. Should not be needed now. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: named tcp dos?

2018-08-03 Thread Matus UHLAR - fantomas
#x27;t think so. minimal-responses only skip unnecessary info, so they should have no effect on TCP retries. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: My IXFR/AXFR stopped suddenly

2018-07-07 Thread Matus UHLAR - fantomas
bigger or the same as the one on the master (or the one in the NOTIFY), slave does not try to xfer the zone. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: My IXFR/AXFR stopped suddenly

2018-07-06 Thread Matus UHLAR - fantomas
2018 14:10:28.341 client x.x.x.x#10090: received notify for -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: What if the link is failed between master/slave

2018-06-29 Thread Matus UHLAR - fantomas
use question marks. There's no functionality in BIND that would keep sending notices to slaves when they are down. It's slaves' job to be up to date. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addre

Re: Reinstall bind9 via apt-get with options

2018-06-29 Thread Matus UHLAR - fantomas
source packages if you want to have them compiled with default options. However, in debian since stretch there's package named bind9-dyndb-ldap that may support what you want. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertisi

Re: Domain name based multihome routing?

2018-06-27 Thread Matus UHLAR - fantomas
to DSL. Note that at my home, most of data is spend by my children watching youtube videos - I don't think that routing general web and streaming services to cell connection would help you with anything. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I

Re: cyberia.net.sa

2018-06-26 Thread Matus UHLAR - fantomas
o-three of them. Some web DNS checkers do great job. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. We are but packets in the Intern

Re: Stopping name server abuse

2018-06-26 Thread Matus UHLAR - fantomas
nfortunately asking him nicely didn't work." it seems unlikely that repeatedly annoying the individual repeatedly will be productive. I believe this can eb the same situation as putting images owned by getty to your website. They will send you invoice with higher price than if you had a con

Re: Stopping name server abuse

2018-06-25 Thread Matus UHLAR - fantomas
asses the time the server would need to construct the response, plus time spent in the network stack. (I'm assuming we don't care about client side "expense".) not responding server will usually receive more queries. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantom

Re: Test mail to bind-users

2018-05-31 Thread Matus UHLAR - fantomas
everyone can set up such configuration and not everyone of those who can is willing to play with it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.

Re: Timeout and SERVFAIL

2018-05-30 Thread Matus UHLAR - fantomas
e often. How can I configure the name servers so failure of one or two doesn't impact the third? Or use multiple master setup and distribute the zone differently than using DNS mechanism. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail ad

Re: location for master file dump

2018-05-27 Thread Matus UHLAR - fantomas
le. that's admin's job. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #98652: Operation co

Re: also-notify and allow-notify

2018-05-18 Thread Matus UHLAR - fantomas
On 18.05.18 23:07, Blason R wrote: Okies so zone xfer would happen on TCP/53 correct and notify would be sent on udp/53? maybe and maybe not. both tcp/53 nd udp/53 are mandatory, and both can be used for any kind of DNS traffic. On Fri, May 18, 2018, 7:31 PM Matus UHLAR - fantomas wrote

Re: RPZ zone update how to sync

2018-05-18 Thread Matus UHLAR - fantomas
. However I would recommend your partner trying master - this way they can fetch the zone even if your slave fails. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAV

Re: also-notify and allow-notify

2018-05-18 Thread Matus UHLAR - fantomas
On 17.05.18 23:00, Blason R wrote: So here I am sending notification to 192.168.5.49 on port 4545; my queries are 1. How do I configure port on slave 4545 so that slave server can start listening on that port. On Fri, May 18, 2018 at 3:02 PM, Matus UHLAR - fantomas wrote: why do you

Re: also-notify and allow-notify

2018-05-18 Thread Matus UHLAR - fantomas
onfigure port on slave 4545 so that slave server can start listening on that port. why do you need to listen on port 4545 instead of default 53? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: n

Re: BIND srtt algorithm not working as expected

2018-05-17 Thread Matus UHLAR - fantomas
ir reputation lookups, it must be the cause of some pretty serious ouages. :-( this kind of protection apparently should not be run on public DNS infrastructure. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this a

Re: notify explicit and also-notify

2018-05-05 Thread Matus UHLAR - fantomas
NOTIFY-UPDATED [i.e. AXFR/IXFR] On Sat, May 5, 2018 at 10:34 PM, Matus UHLAR - fantomas wrote: source port: random. destination port: 53 (standard DNS port). you don't need to enable different ports unless you can't do stateful firewall On 05.05.18 22:53, Blason R wrote: Absolutely t

Re: notify explicit and also-notify

2018-05-05 Thread Matus UHLAR - fantomas
NOTIFY-UPDATED [i.e. AXFR/IXFR] source port: random. destination port: 53 (standard DNS port). you don't need to enable different ports unless you can't do stateful firewall -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adve

Re: notify explicit and also-notify

2018-05-04 Thread Matus UHLAR - fantomas
correct -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 99 percent of lawyers give

Re: what's wrong with recent bind-utils against dnsmasq

2018-04-27 Thread Matus UHLAR - fantomas
ple.com. 30 IN A 127.0.0.1 dig by default only asks for A which is why you got proper answer here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT aku

Re: problems changing NS records

2018-04-26 Thread Matus UHLAR - fantomas
b.org names.sulweb.org You must have A records for all of your nameservers. " ...not mentioning that sulweb.org itself is hosted by seflow.net which makes it inapt too... find better nameservers for your domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning:

Re: Queries to DNS Blackholes don't respond

2018-04-18 Thread Matus UHLAR - fantomas
your provider. BLACKHOLE-1.IANA.ORG (192.175.48.6) BLACKHOLE-2.IANA.ORG (192.175.48.42) Is it OK that I do? Are blackholes servers useful for this purpose ? I believe that the meaning of "blackhole" is that those servers will NOT respond. -- Matus UHLAR - fantomas, uh...@fan

Re: Wildcard prefix

2018-04-12 Thread Matus UHLAR - fantomas
uld complain about out of zone data. why do you say there's a dot needed? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I feel like

Re: Wildcard prefix

2018-04-12 Thread Matus UHLAR - fantomas
don't want to install if this is not my best option. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 42.7 percent of all statistics are

Re: BIND question

2018-04-12 Thread Matus UHLAR - fantomas
mailhosting.example -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfamiliar territory

Re: Stealth NS records

2018-03-30 Thread Matus UHLAR - fantomas
t the domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user friendly, it's just selective who its f

Re: Odd behavior on a secondary server

2018-03-22 Thread Matus UHLAR - fantomas
missing something. it's AFAIK a way to record when ther was last refresh attempt. I don't know of any better way to records that -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto ad

Re: Bind 9.9 upgrade and RFC 1918 Errors

2018-03-14 Thread Matus UHLAR - fantomas
.192.in-addr.arpa is only for one IP - 192.168.1.0. for 192.168.1.0/24 you need reverse zone 1.168.192.in-addr.arpa -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT aku

Re: CNAME at apex, was Re: Issue running "dig txt rs.dns-oarc.net" on 9.12

2018-03-10 Thread Matus UHLAR - fantomas
stake and expecting it to work. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Two words: Windows survives." - Craig Mundie, Mi

Re: Suggestions for a distributed DNS zone hosting solution I'm designing

2018-03-09 Thread Matus UHLAR - fantomas
re nameserver IPs in different IP ranges, so they could refise register domains to your anycast servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu po

Re: Zone transfer Denied

2018-03-07 Thread Matus UHLAR - fantomas
x.ip6.arpa/AXFR/IN' denied---* What am i missing?? you did not allow client ::0:xx:::: to transfer the zone 0.0.0.0.0.0.0.0.0.0.0.0.x.x.0.0.0.0.0.0.8.b.3.4.1.0.0.2.ip6.arpa from the master. -- Matus UHLAR - fantomas, uh...@f

Re: SOA Minimum comment in "dig" output

2018-02-12 Thread Matus UHLAR - fantomas
;dig' source code yet. Because minimum is what it is? It's not negative caching ttl, see above. while called "minimum", as the OP correctly noted, it's defined as TTL for negative responses. describing it as "negative TTL" would be correct. -- Matus UHLA

Re: Saurabh: Error while adding the Domain into RPZ as Bad Name.

2018-02-12 Thread Matus UHLAR - fantomas
g> , the A Record shows me as IP 8.8.8.8.* there are nameservers who do not enforce the requirement above. However, I don't recommend violating the requirement. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising t

Re: Minimum TTL?

2018-02-10 Thread Matus UHLAR - fantomas
re are many ways to fsck things up, and many ways wayt so avoid that. forcing min-ttl is way to avoid one, although it can cause what you describe. But I do not create loops and would like a possibility to avoid the latter case. Note that I am able to coifigure BIND to avoid loops, but I can'

Re: Minimum TTL?

2018-02-10 Thread Matus UHLAR - fantomas
rcing a 5s minumum leads to serious problems? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One OS to rule them all, One OS to find them,

Re: Minimum TTL?

2018-02-09 Thread Matus UHLAR - fantomas
k admins. been there too... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I don't have lysdexia. The Dog

Re: Minimum TTL?

2018-02-08 Thread Matus UHLAR - fantomas
rgency=low [Michael Milligan] * Add min-cache-ttl and min-ncache-ttl keywords [LaMont Jones] * Fix merge errors from 9.6.0.dfsg.P1-0 -- LaMont Jones Fri, 20 Mar 2009 15:50:50 -0600 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: disable dnssec for particular domain

2018-02-08 Thread Matus UHLAR - fantomas
rational solution. What you should do is add some nameservers to the registration (serving an empty zone or something), so that the .eu nameservers return a NODATA response instead of an NXDOMAIN response. Then your private zone will work. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.

Re: disable dnssec for particular domain

2018-02-07 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas wrote: I wonder why does it do that. I have configured a zone to be type forward and expected it to work as confdigured, not be validated upstream. On 07.02.18 14:14, Tony Finch wrote: Validation is mostly independent of resolution, so even if you configure a zone

Re: disable dnssec for particular domain

2018-02-07 Thread Matus UHLAR - fantomas
contact to the registrator. I currently see the only option to disable dnssec on the server, or upgrade to 9.11 ... but I'll upgrade the server to debian 8 (bind9.9.5) first. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adverti

Re: disable dnssec for particular domain

2018-02-07 Thread Matus UHLAR - fantomas
On 06/02/2018 16:31, Matus UHLAR - fantomas wrote: what's the difference, when the domain doesn't exist? is it because .eu is signed? On 06.02.18 16:35, Ray Bellis wrote: Perhaps, although I'm not sure why given that .eu is signed with NSEC3 and opt-out. Are you *sure*

Re: disable dnssec for particular domain

2018-02-06 Thread Matus UHLAR - fantomas
Am 2018-02-06 hackte Matus UHLAR - fantomas in die Tasten: our customer uses a domain that is registered, but hidden (doesn't exist in DNS). On 06.02.18 18:24, Michelle Konzack wrote: I hope you know what are you doing, because the DNS MUST exist! Please read the general conditions for t

Re: disable dnssec for particular domain

2018-02-06 Thread Matus UHLAR - fantomas
On 06/02/2018 16:00, Matus UHLAR - fantomas wrote: our customer uses a domain that is registered, but hidden (doesn't exist in DNS). The domain is used by multiple organizations and we are required to forward lookups for the domain to foreign internal servers. The problem is, that p

disable dnssec for particular domain

2018-02-06 Thread Matus UHLAR - fantomas
I do anything other on my side than disabling DNSSEC validation at all? I have bind9.8, going to upgrade to 9.9.5 (could probably go to 9.11 if needed) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na

Re: nested CNAMEs resolution failures?

2018-01-29 Thread Matus UHLAR - fantomas
DNS server. this way you just delegate your problem at 3rd-party (although google) servers. I wonder if it's possible and useful to use the same fallback mechanism to disable cookies as is used to disable EDNS or to reduce UDP size... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://

Re: Reverse DNS conditional forwardning

2018-01-25 Thread Matus UHLAR - fantomas
, each cross delegating the others part, and things work out quite well. this may "work" when you have your own reverze zone and agree with other owners on sharing. But from the internet, and from the DNS point of view, you are creating problematic mess. -- Matus UHLAR - fantomas, uh...@fan

Re: Round-robin

2018-01-24 Thread Matus UHLAR - fantomas
wo clients asking repeatedly could get still the same answer. Also note that intermediate servers may change the order (although they should not). I even encountered case where resolver library (libnss_lwres IIRC) ordered the list and still provided in the same order. -- Matus UHLAR - fantomas,

Re: Update ACLs dynamically

2018-01-19 Thread Matus UHLAR - fantomas
use VPN -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Chernobyl was an Windows 95 beta test site

Re: Reverse DNS conditional forwardning

2018-01-18 Thread Matus UHLAR - fantomas
On 01/18/2018 03:44 AM, Matus UHLAR - fantomas wrote: what you search for is the Classless IN-ADDR.ARPA delegation, described in RFC2317 On 18.01.18 09:39, Grant Taylor via bind-users wrote: Classless IN-ADDR.ARPA delegation likely won't work if all IPs involved are not configured f

Re: Reverse DNS conditional forwardning

2018-01-18 Thread Matus UHLAR - fantomas
Classless IN-ADDR.ARPA delegation, described in RFC2317 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "To Boot or not to Boot, that&

Re: Zone give from one second to another error...

2017-12-24 Thread Matus UHLAR - fantomas
. Unfortunately I have not gotten bind9 running with PostgreSQL yet which is realy annoying. add the dns3 or fix dns2 ASAP - .net servers only provide one functional nameserver and when it'd down, people won't see your domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http:/

Re: Creating a blackhole zone...

2017-12-24 Thread Matus UHLAR - fantomas
.net. 2) I'm not confident that you can use a CNAME with a wildcard record. this is not a problem. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Domain Not Resolving

2017-11-21 Thread Matus UHLAR - fantomas
all domains that contain hosts should have a "localhost" A record in them note that rfc 1537 has been obsoleted (>20 years ago) by rfc 1912 that does not contain this test. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail a

Re: Different forwarder for certain response ip (result ip )

2017-09-16 Thread Matus UHLAR - fantomas
orward togoogle, you could use dnsmasq as well. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I intend to

Re: Different forwarder for certain response ip (result ip )

2017-09-16 Thread Matus UHLAR - fantomas
ts as forwarders. that explains why you want forwarders on port 443. But it doesn't explain why you forward to google. I still think it's useless, unless your ISP blocks port 53 to public servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: Different forwarder for certain response ip (result ip )

2017-09-16 Thread Matus UHLAR - fantomas
t 443; 208.67.220.220 port 443; }; 1. who runs DNS servers on port 443? 2. you can configure port for DNS server in server {} statement. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varo

Re: Strange recursor response time pattern

2017-09-05 Thread Matus UHLAR - fantomas
ay be result of this algorithm. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfam

Re: Need DNS records help for single server (and IP), and multi-domain mail server.

2017-08-24 Thread Matus UHLAR - fantomas
mail.example.com. @ IN TXT "v=spf1 mx -all" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Ch

Re: DNS traffic accounting

2017-07-23 Thread Matus UHLAR - fantomas
having to deal with squid stats and cache) On Jul 23, 2017 16:19, "Matus UHLAR - fantomas" wrote: again: why don't you simply traffic between the bind server and clients? On 23.07.17 16:53, Abi Askushi wrote: Because i would like to avoid counting traffic for cached respons

Re: DNS traffic accounting

2017-07-23 Thread Matus UHLAR - fantomas
having to deal with squid stats and cache) again: why don't you simply traffic between the bind server and clients? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: DNS traffic accounting

2017-07-18 Thread Matus UHLAR - fantomas
generate WAN traffic. well, caching makes your benefit, doesn't it? Any suggestion how to approach this problem? ...don't? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto ad

Re: delegation NS records

2017-07-14 Thread Matus UHLAR - fantomas
rvers in your owndomain (and thus glue recods in parent zone), search for nameservers that do have glue records in parent zone. This will lower a risk of breaking the delegation path. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advert

Re: designing the DNS from the scratch

2017-07-10 Thread Matus UHLAR - fantomas
he path, so the 3ms can only be achieved on short distances. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only substitute for good

Re: restarting bind fixes some resolution issues

2017-07-09 Thread Matus UHLAR - fantomas
mirl.cloudfront.net - maybe you should look up that one next time problem appears. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I intend to li

Re: wildcard not working after record deleted

2017-06-20 Thread Matus UHLAR - fantomas
one data, and I do understand that prevents you from helping. I was hoping someone else had come across this at some point. note that existande of "something.sample" subdomain also means that "sample" exists and is empty. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: reverse dns configuration for IPV4, IPV6+ dns+ mail ?

2017-06-19 Thread Matus UHLAR - fantomas
Am 19.06.2017 um 16:56 schrieb Matus UHLAR - fantomas: since DNS don't care about the PTR but mail does what is your problem that you need stupid dicussions instead just agree that it can't do harm and in doubt is beneficial to have just one hostname, use that one hostname in hel

Re: reverse dns configuration for IPV4, IPV6+ dns+ mail ?

2017-06-19 Thread Matus UHLAR - fantomas
Am 19.06.2017 um 15:25 schrieb Matus UHLAR - fantomas: those rejections were NOT caused by having two different PTRs. They were caused by something different that is not a subject of this thread - even one PTR of this format would cause rejections. On 19.06.17 15:32, Reindl Harald wrote: not

Re: reverse dns configuration for IPV4, IPV6+ dns+ mail ?

2017-06-19 Thread Matus UHLAR - fantomas
one PTR of this format would cause rejections. in all of these cases just remove the old useless generic PTR would have solved the problem from the start so please inform yourself and do tests. go reread the OP's question. He asked about "ns" and "mail" records. t

Re: reverse dns configuration for IPV4, IPV6+ dns+ mail ?

2017-06-19 Thread Matus UHLAR - fantomas
rrect. * smtp_helo_name of your MTA matches the same name this one is incorrect and my next comment applies only to this one: Am 19.06.2017 um 08:49 schrieb Matus UHLAR - fantomas: Even this is not required. In fact, requiring this breaks SMTP RFC. The only requirement on helo name is that host must exist a

Re: reverse dns configuration for IPV4, IPV6+ dns+ mail ?

2017-06-19 Thread Matus UHLAR - fantomas
apparently yes, because this thread exists. There's OP confused about a problem that does not exists. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

<    1   2   3   4   5   6   7   8   9   10   >