Re: Zone transfer Denied

2018-03-07 Thread Matus UHLAR - fantomas
.arpa/AXFR/IN' denied---* What am i missing?? you did not allow client ::0:xx:::: to transfer the zone 0.0.0.0.0.0.0.0.0.0.0.0.x.x.0.0.0.0.0.0.8.b.3.4.1.0.0.2.ip6.arpa from the master. -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: Bind 9.9 upgrade and RFC 1918 Errors

2018-03-14 Thread Matus UHLAR - fantomas
only for one IP - 192.168.1.0. for 192.168.1.0/24 you need reverse zone 1.168.192.in-addr.arpa -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu p

Re: Wildcard prefix

2018-04-12 Thread Matus UHLAR - fantomas
want to install if this is not my best option. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 42.7 percent of all statistics are made up

Re: BIND question

2018-04-12 Thread Matus UHLAR - fantomas
mailhosting.example -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfamiliar territory

Re: Wildcard prefix

2018-04-12 Thread Matus UHLAR - fantomas
uld complain about out of zone data. why do you say there's a dot needed? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I feel like I'm d

Re: Queries to DNS Blackholes don't respond

2018-04-18 Thread Matus UHLAR - fantomas
provider. BLACKHOLE-1.IANA.ORG (192.175.48.6) BLACKHOLE-2.IANA.ORG (192.175.48.42) Is it OK that I do? Are blackholes servers useful for this purpose ? I believe that the meaning of "blackhole" is that those servers will NOT respond. -- Matus UHLAR - fantomas, uh...@fantomas

Re: Stealth NS records

2018-03-30 Thread Matus UHLAR - fantomas
the domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user friendly, it's just selective who its friends

Re: Odd behavior on a secondary server

2018-03-22 Thread Matus UHLAR - fantomas
missing something. it's AFAIK a way to record when ther was last refresh attempt. I don't know of any better way to records that -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: problems changing NS records

2018-04-26 Thread Matus UHLAR - fantomas
b.org names.sulweb.org You must have A records for all of your nameservers. " ...not mentioning that sulweb.org itself is hosted by seflow.net which makes it inapt too... find better nameservers for your domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warni

Re: resolve - send query via specific network device

2018-10-24 Thread Matus UHLAR - fantomas
/routing-tables.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. There's a long-standing bug relating to the x86 architecture that allows yo

Re: forward zone

2018-10-27 Thread Matus UHLAR - fantomas
end queries because it is not "trusted" As you can't have "allow-query" in a zone of type "forward", I don't find any nice solution. Le 26/10/2018 à 09:21, Matus UHLAR - fantomas via bind-users a écrit : You can and you also need to add allow-query for it.  However, since

Re: concurrent-session

2018-11-04 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Despite the cost of living, have you noticed how popular it remains

Re: Enforcing minimum TTL...

2018-10-26 Thread Matus UHLAR - fantomas
risky, and forcing minimum TTL is apparently not way to work around. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. REALITY.SYS corrupted

Re: forwarder selection logic by bind9

2018-11-11 Thread Matus UHLAR - fantomas
see if situation has changed. BIND does not differ between servers as primary and secondary. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.

Re: Method of writing zone files

2018-11-13 Thread Matus UHLAR - fantomas
journals to be synced and files saved. You can call this before backup and call rndc thaw after. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklam

Re: conflicting subdomain delegation

2018-11-13 Thread Matus UHLAR - fantomas
he b.a.com is delegated, no subdomains of it should appear in a.com zone. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is

Re: conflicting subdomain delegation

2018-11-16 Thread Matus UHLAR - fantomas
lapps.com.172800 IN NS ns-33.awsdns-04.com. c.b.jilapps.com.172800 IN NS ns-540.awsdns-03.net. servers for c.b.jilapps.com send this, servers for jilapps.com send referrals to c.b.jilapps.com servers -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ W

Re: DNS Query from different Subnet

2018-11-15 Thread Matus UHLAR - fantomas
this is not possible with BIND, you must define zhole zone. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do you want to go t

Re: unable to resolve evisa.dgdi.ga FQDN

2018-10-09 Thread Matus UHLAR - fantomas
edns.com. ns2.francedns.com and ns3.francedns.com return SERVFAIL. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. - Have you got anything without

Re: Beginner - Bind - Bad dotted quad

2018-09-24 Thread Matus UHLAR - fantomas
200.fin.local. @ IN A 192.168.1.159 x200 IN A 192.168.1.159 www IN A 192.168.1.159 pfsense IN A 192.168.1.1 hp4000 IN A 192.168.1.12 there's apparently invalid space character on the line above. nstation10 IN A 192.168.1.104 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning:

Re: NTP through DNS?

2018-09-22 Thread Matus UHLAR - fantomas
ration we know of, unless DHCP that was reported often not to work. using either CNAME or SRV records won't change the fact that ntp server does not autoconfigure itself. Neither of them also changes the fact that the NTP configuration is not related to domain, but to the local network. -- Matus UHLAR

Re: NTP through DNS?

2018-09-25 Thread Matus UHLAR - fantomas
09.18 10:00, Danny Mayer wrote: In your domain file add entries like this: this is called local configuration. Simple enough? No. It requires local configuration of NTP server. in that case, DNS-side solution is useless. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: Upgrade help with Bind 9.12

2018-09-12 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Honk if you love peace and quiet. ___ Please

Re: load balancing

2018-09-19 Thread Matus UHLAR - fantomas
ficiently undefined that it cannot really be answered :-) What *exactly* is the question / scenario you are asking? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Not receiving "Fixed/Ordered" query response

2019-01-25 Thread Matus UHLAR - fantomas
t does not support "fixed" ordering by default. Fixed ordering can be enabled at compile time by specifying "--enable-fixed-rrset" on the "configure" command line. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail ad

Re: Problem with zone delegation with private gTLD

2019-04-08 Thread Matus UHLAR - fantomas
users/organizations use private TLDsm, just like they often use private IP ranges instead of public. I believe there should be reserved gTLD for such usage. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Help: BIND _ Recursive query

2019-03-04 Thread Matus UHLAR - fantomas
the default, so if you remove it, it stays set to yes (unless it's set to "no" somewhere). recursion is the feature that allows BIND to resolve domains not configured locally, you surely need it enabled. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NO

Re: Server can not resolve Domain

2019-02-21 Thread Matus UHLAR - fantomas
mail named[4833]: all zones loaded Feb 20 21:40:16 mail named[4833]: running do you actually have the "my.domain" in your nameserver configuration? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Combining forward with master zone.

2019-02-21 Thread Matus UHLAR - fantomas
8.8.8.8;}; On 20.02.19 16:08, Kevin Darcy wrote: Delegate needs.example.com from example.com and you should be set. if this is not clear enough, it means that the "example.com" zone stored in "static/antiphish.db" file must contain NS record for "needs": nee

Re: DNS load balancing: UDP or TCP ?

2019-02-20 Thread Matus UHLAR - fantomas
Roberto Carna wrote: Can you confirm thgis is true in 100% of clients??? On 20.02.19 14:11, Tony Finch wrote: It's true of clients that follow the spec. I would like to add that the spec mentions there mey be clients that use only TCP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re:

2019-02-20 Thread Matus UHLAR - fantomas
.default-zones"; > > named.conf.default-zones: > recursion yes; > zone "teamviewer.com" { > type forward; > forwarders { 8.8.8.8; }; > }; > > named.conf.local: > -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT

Re: Problems removing a domain

2019-03-06 Thread Matus UHLAR - fantomas
: QUERY, status: SERVFAIL, id: 57790 Op 05-03-19 om 16:32 schreef Matus UHLAR - fantomas: SERVFAIL here. ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION

Re: Problems removing a domain

2019-03-05 Thread Matus UHLAR - fantomas
have forwarding set to a server which does know the domain. can you use "dig" instead of "host" to see what does your BIND know? dig any extensus.nl. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to

Re: Problems removing a domain

2019-03-05 Thread Matus UHLAR - fantomas
l localhost ;; Got SERVFAIL reply from ::1, trying next server Server: localhost Address:127.0.0.1#53 ** server can't find extensus.nl: SERVFAIL root@ns1:/usr/local/sbin# -- this is in fact the same result, using the obsolete "nslookup" command see the SERVFAIL in dig outpu

Re: Help: BIND _ Recursive query

2019-03-03 Thread Matus UHLAR - fantomas
ng the zone configuration for resolving internal machines ,whether it make sense to use "recursion yes" or not "recursion yes" is required when you need to resolve outside zones. That means, for most cases it's required for BIND to work. -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: Help: BIND _ Recursive query

2019-03-03 Thread Matus UHLAR - fantomas
On 03.03.19 07:36, vivek wrote: thanks, that means for Bind service to work we have to have the "recursion yes" else the forwarder will also not work. Actually I m bit confused between Recursive vs Iterative query mode , so does this mean Bind will only work in Recursive query mode & this

Re: Help: BIND _ Recursive query

2019-03-11 Thread Matus UHLAR - fantomas
gone, but it still has a leftover "recursion yes" >> clause. Am I correct is assuming that this is now useless and can >> be removed? On 04.03.19 16:33, Niall O'Reilly wrote: >If you want "general caching DNS service" to continue to work, >you'll need to keep &

Re: BIND 9.11 no longer respects edns-udp-size?

2019-03-12 Thread Matus UHLAR - fantomas
will retrieve all of the required information (SOA, NS, and supporting A/ records) to successfully insert the zone apex into the cache. isn't SOA response limited in an ongoing RFC draft? that would bereak stub zones too... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: Forward zone inside a view

2019-02-07 Thread Matus UHLAR - fantomas
m resolve just teamviewer.com. How can I do to forward only teamviewer.com zone queries to my resolvers??? what is the point of running DNS server with only two hostnames allowed to resolve? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail a

Re: Forward zone inside a view

2019-02-09 Thread Matus UHLAR - fantomas
(and this is not what I want, it's what I'm trying to prevent)) So can you help me please??? you still have not answered my question: what is the point of running DNS server with only two hostnames allowed to resolve? However, you can define empty type master "." zone, and bind wi

Re: Forward zone inside a view

2019-02-11 Thread Matus UHLAR - fantomas
warders to 8.8.8.8. However, BIND can do resolution well without forwarding. Also, this seems to be just the opposite wht you describe above. El sáb., 9 feb. 2019 a las 12:28, Matus UHLAR - fantomas () escribió: On 07.02.19 16:30, Roberto Carna wrote: >Desktops I mentioned can only access to web a

Re: SSHFP observation

2019-01-31 Thread Matus UHLAR - fantomas
nts. Garbage in, garbage out. I see no bug. well, either BIND should reject those records as invalid and not to send them, or dig (from bind package) should not complain about malformed responses. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-m

Re: DNS-FLAG-Day

2019-01-28 Thread Matus UHLAR - fantomas
On 28.01.19 13:28, Umut Arus wrote: Don't forget check your IPS. Some IPS rules and tcp ACL can block the requests. For example, our Checkpoint IPS stopped the requests. were they requests from you as client or to you as server? On Mon, Jan 28, 2019 at 1:14 PM Matus UHLAR - fantomas via bind

Re: Problem with zone delegation with private gTLD

2019-04-08 Thread Matus UHLAR - fantomas
On 08/04/2019 13:05, Matus UHLAR - fantomas wrote: > I believe there should be reserved gTLD for such usage. On Mon, 8 Apr 2019 at 10:35, Xavier Humbert wrote: Is this not what the TLD /.invalid/ is supposed to be ? On 08.04.19 13:18, Matthew Pounsett wrote: RFC2606 reserves test, exam

Re: Change DNS records automatically when a link is DOWN

2019-06-06 Thread Matus UHLAR - fantomas
; monitors the main Internet link and in case it is DOWN automatically order to modify the FQDN records in DNS3 ??? can't your provider set you up a routing failover? While it's doable in DNS, it has some drawbacks (requires short TTL) and mainly: DNS is not designed to do this kind of stuff. -- M

Re: Question about at zone transfer behaviour on slave

2019-06-06 Thread Matus UHLAR - fantomas
immediately. Unless, there's too many zone transfers in which case BIND delays the transfer. Also, there may be too many transfers on the master and it may refuse the zone transfer temporarily. See the transfers-in and transfers-out BIND options. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: writeable file '/etc/bind/db.empty' already in use

2019-06-23 Thread Matus UHLAR - fantomas
signing globally? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Enter any 12-digit prime number to continue

Re: Bind and HTTPS?

2019-07-11 Thread Matus UHLAR - fantomas
DNSSEC enough to assure integrity? and, how shall we resolve names of those HTTPS servers? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: max file size or line count for BIND zone file

2019-04-26 Thread Matus UHLAR - fantomas
rset="UTF-8" I would guess that lbutlr's complaint goes to HTML generated. Holy sh*t, it looks as ugly as html mail generated in MS-Word from some 15 years ago generallym, plaintext is better for use in mailing lists ... and sorry for OT, I shut up now -- Matus UHLAR - fantomas

Re: Bind with views: forward any public domain in one view

2019-08-15 Thread Matus UHLAR - fantomas
ote that BIND can do the same that google servers (8.8.8.8) can do, and you'll avoid one hop. simply don't forward but let BIND to resolve. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adr

Re: EDITED: Proper Way to Configure a Domain which never sends emails

2019-08-19 Thread Matus UHLAR - fantomas
points to those addresses). To avoid this, you can point the MX for the domain to ".", some MTAs understand this as "this domain doesn't provide mail service". -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adverti

Re: factor addresses out of 'forwarders' statement

2019-07-19 Thread Matus UHLAR - fantomas
or their nameservers are unreachable. If not, you can try using stub or static-stub zone and named masters list. yes, this is case where it would be greas to use masters for forward zones. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receiv

Re: CNAME as an alias to a TXT record

2019-11-06 Thread Matus UHLAR - fantomas
re or less as expected, the following dig command fails to return a record. dig -t TXT _acme-challenge.dom1.com is is supposed to work this way. If it doesn't, you have an error somewhere. Are you sure that there's no other _acme-challenge.dom1.com record than the CNAME? -- Matus UHLAR - fa

Re: CNAME as an alias to a TXT record

2019-11-06 Thread Matus UHLAR - fantomas
On 04.11.19 12:30, Computerisms Corporation wrote: I am wondering if it is possible to create a CNAME in one zone to resolve as a TXT record in another zone. On 06.11.19 09:48, Matus UHLAR - fantomas wrote: CNAME will not resolve as a TXT. CNAME will make ALL types queries for original query

Re: DNS queries go to primary and secondary DNS servers at the same time

2019-12-16 Thread Matus UHLAR - fantomas
at the same time. maybe modified version of the "host" command? What can be the problem ? Because I expect only DNS traffic going to DNS1 because it is before DNS2 in /etc/resolv.conf. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: Zoneformat

2019-10-28 Thread Matus UHLAR - fantomas
OMAIN) [root@ns1 named]# named-checkzone crm365app crm365app.cyberia.net.sa.hosts zone crm365app/IN: loaded serial 2015034459 OK is your server in resolv.conf? What does log say when you reload named? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: Log rolling stopped working in 9.11.12 ?

2019-11-20 Thread Matus UHLAR - fantomas
not apply for packages outside of centos. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Windows found: (R)emove, (E)rase, (D)elete

Re: Delegation not working from slave.

2019-10-08 Thread Matus UHLAR - fantomas
(which I can't clearly extract from your message)? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Windows 2000: 640 MB ought to be enough fo

Re: bind as "reverse-proxy"

2020-02-26 Thread Matus UHLAR - fantomas
authoritative server, or you have not. What is the point of your request? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do you want

Re: Getting all IP adresses for a domain name

2020-01-29 Thread Matus UHLAR - fantomas
nd to send different IPs for different clients, often just the one that is tropologically closest to the client. Unfortunately, such CDNs don't provide all possible addresses so I guess you are unlucky here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: BIND - in loop rewrite zone serial no.

2020-01-28 Thread Matus UHLAR - fantomas
s.isc.org/mailman/listinfo/bind-users -- End of bind-users Digest, Vol 3356, Issue 1 *** " ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.o

Re: Unable to completely transfer root zone

2020-02-14 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas wrote: If you use cisco routers, ask network admins to disable any DNS "fixup" functionality, because that usually causes problems. On 14.02.20 12:47, Tony Finch wrote: In my experience all Cisco PIX/ASA fuxup options are horribly broken and should be turne

Re: Weird behaviour in wildcard CNAME - is this feature or bug? Can it be changed?

2020-02-11 Thread Matus UHLAR - fantomas
empty domain payis.prod.app.pcp.cn.prod, and since it exists (although empty), the *.prod.app.pcp.cn.prod does not apply to payis.prod.app.pcp.cn.prod nor to any subdomain under it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Unable to completely transfer root zone

2020-02-14 Thread Matus UHLAR - fantomas
internet? one bind is superflous there, isdn't it? The error above occurred on the forwarding bind in the proxy dmz. so the problem firewall is between "forwarding bind" and "internet bind" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wi

Re: BIND Workaround for Broken DNS

2020-01-18 Thread Matus UHLAR - fantomas
fix it. knowing their DNS when they are at home and use mobile data, plus a few requests to google DNS could change their "it works when..." I don't know how google DNS works, some reported it not following standard much. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fa

Re: Problem to transfer reverse zone DNS on secondary DNS servers

2019-12-31 Thread Matus UHLAR - fantomas
On 12/30/19 12:07 PM, Matus UHLAR - fantomas wrote: of course. On 30.12.19 14:30, Grant Taylor via bind-users wrote: The idea of an ISP telling me how to configure my DNS server causes indigestion, possibly severe. My registrar, the parent domain owner / operator, doesn't get to tell me

Re: Problem to transfer reverse zone DNS on secondary DNS servers

2019-12-27 Thread Matus UHLAR - fantomas
.in-addr.arpa 30.246.2.186.in-addr.arpa rfc 2317 describes how reverse DNS should be set up and it should work automatically. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Problem to transfer reverse zone DNS on secondary DNS servers

2019-12-30 Thread Matus UHLAR - fantomas
. Initial configuration is another story. That will likely involve configuration at both ends. I.e. ISP delegating to customer and customer configuring their name server appropriately. On 12/27/19 10:48 AM, Matus UHLAR - fantomas wrote: the ISP should the client what zone to configure

Re: Problem to transfer reverse zone DNS on secondary DNS servers

2019-12-27 Thread Matus UHLAR - fantomas
On 12/27/19 7:04 AM, Matus UHLAR - fantomas wrote: there's obviously something broken in this setup. You don't have to call the ISP if the reverse DNS changes. On 27.12.19 08:58, Grant Taylor via bind-users wrote: Why do you say that? What do you see that's broken in the OP's configuration

Re: Problem to transfer reverse zone DNS on secondary DNS servers

2019-12-27 Thread Matus UHLAR - fantomas
The only thing that I saw was a slip in that there is something outside the local DNS server that needs to be configured for reverse DNS. Am 27.12.19 um 18:48 schrieb Matus UHLAR - fantomas: I think that it should be either change local DNS or call ISP to change it, not both at once.  Having

Re: Fwd: Re: recursive resolver

2020-03-12 Thread Matus UHLAR - fantomas
< shubhamgo...@cdac.in <mailto:shubhamgo...@cdac.in> > wrote: Dear sir, how can we improve my DNS Recursive resolver speed. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to

Re: oddity with trubuiltpambula.com.au

2020-04-19 Thread Matus UHLAR - fantomas
to themselves, so why the different names? it's common when registrar is not the same as DNS master. better contact either to fix that While it may work, it can also cause unexpected problems. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: how can we restart bind-9.14.11

2020-03-16 Thread Matus UHLAR - fantomas
install from tar file, you must maintain it yourself (fix security bugs etc). I recommend installing from distro. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: bind 9.11.2 - domain and subdomain with one zone does not work

2020-04-03 Thread Matus UHLAR - fantomas
s a valid option and it worked in small scale on the testsystem, so we decieded to go this way. If this needs to be changed, I need a reason besides of 'that is this way more easy', because these zones get generated from an automated system and I need an argument to get a permission for a change request.

Re: bind 9.11.2 - domain and subdomain with one zone does not work

2020-04-03 Thread Matus UHLAR - fantomas
an automated system and I need an argument to get a permission for a change request. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: bind 9.11.2 - domain and subdomain with one zone does not work

2020-04-03 Thread Matus UHLAR - fantomas
On 03.04.20 14:20, David Alexandre M. de Carvalho wrote: Where can I find about alternatives to point 2? I have a windows subdomain configured in that way, never realized there was a better way. On 03.04.20 16:35, Matus UHLAR - fantomas wrote: if you want to have subdomain with different set

Re: How to get random subset of large rrset (30+ IPs for round robin)?

2020-03-20 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. WinError #98652: Operation completed successfully

Re: How to get random subset of large rrset (30+ IPs for round robin)?

2020-03-21 Thread Matus UHLAR - fantomas
list, but this sounds like an almost >perfect example of PowerDNS's LUA record type (or something with >CoreDNS) >Other than that, the only thing I can think of is BIND with DLZ and a >database that returns a random subset from a DB query, but that sounds >awful... On Fri, Mar 20, 2

Re: "forward first" set on a master zone not working as expected

2020-09-03 Thread Matus UHLAR - fantomas
DOMAIN note that nslookup is very bad program for tracking DNS errors. use "host" or "dig" for that case. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chc

Re: forwarders used in order or based on RTT ?

2020-10-16 Thread Matus UHLAR - fantomas
selected based on an RTT(round-trip-time)-based algorithm" So which is correct? both are. The ARM does not say they are queried in defined order. The order is defined by RTT And did it change at some point? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I w

Re: Malformed transaction errors

2020-10-19 Thread Matus UHLAR - fantomas
rimary on on machine and a secondary server on a separate machine. Errors are on the primary server.) what's the primary server? maybe broken DNS implementation -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Var

Re: Error "Query section mismatch : got"

2020-08-19 Thread Matus UHLAR - fantomas
ey should not block it. again, why you query for 250.0-24.199.212.125.in-addr.arpa ? under normal circumstances there's no point of querying that name. there -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addre

Re: Error "Query section mismatch : got"

2020-08-19 Thread Matus UHLAR - fantomas
On Wed, Aug 19, 2020 at 7:42 AM Matus UHLAR - fantomas wrote: again, why you query for 250.0-24.199.212.125.in-addr.arpa under normal circumstances there's no point of querying that name. On 19.08.20 10:05, tale via bind-users wrote: Well yes and no. While an individual user would

Re: Error "Query section mismatch : got"

2020-08-21 Thread Matus UHLAR - fantomas
ried to query directly to the hosting that managed it to determine the cause. your query of course makes sense under there curcumstances. But delegating /24 subnet using RFC2317 delegation is useless, because in fact you can delegate whole /24 directly >> On Wed, Aug 19, 2020 at 7:42 AM Mat

Re: Error "Query section mismatch : got"

2020-08-19 Thread Matus UHLAR - fantomas
On 20 Aug 2020, at 00:41, Matus UHLAR - fantomas wrote: On Wed, Aug 19, 2020 at 7:42 AM Matus UHLAR - fantomas wrote: again, why you query for 250.0-24.199.212.125.in-addr.arpa under normal circumstances there's no point of querying that name. On 19.08.20 10:05, tale via bind-users wrote

Re: VS: CNAME / TXT

2020-08-24 Thread Matus UHLAR - fantomas
tware with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: different TTLs for multiple TXT records

2020-09-26 Thread Matus UHLAR - fantomas
means it's not there. This is not just documented standard - doing it differently would make DNS unreliable. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rekl

Re: It is too hard for me to read from this mailing list

2020-09-22 Thread Matus UHLAR - fantomas
in one email. Let the reader focus on one subject. I am using Thunderbird to read the emails. Should I use something else to read it? Any suggestions are welcome. This is my feeling. But, maybe you are happy with it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: How to compute db.192.168.x names from network addresses ?

2020-10-01 Thread Matus UHLAR - fantomas
verlooked something ? it's just a file name. You can use "myrevzone" as long, but using db.192.168.42 is much more explanatory. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adres

Re: Upgrade from 9.14 to 9.16 - transfer-source with low source port no longer works.

2020-05-26 Thread Matus UHLAR - fantomas
-forgery-resilience-05 I guess source port 53 was meant long ago to avoid DNS from being firewalled. However nowadays it's long time obsolete and unsecure. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie

Re: CNAME restrictions

2020-08-04 Thread Matus UHLAR - fantomas
*.datavoiceint.com will cover .datavoiceint.com but not anything under it. you will have to strip the part or get other certificate. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: [Non-DoD Source] Re: Dumb Question is an A or AAAA record required?

2020-07-09 Thread Matus UHLAR - fantomas
pretty sure this is *technically* allowed, but is it really OK to do or are there reasons not to do this?) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Dumb Question is an A or AAAA record required?

2020-07-09 Thread Matus UHLAR - fantomas
y returned NODATA for MX record (effectively saying there's no MX). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam = (S)tupid (P)eople's (A)

Re: [Non-DoD Source] Re: [DoD Source -- ssshhhh Top Secret] Re: Dumb Question is an A or AAAA record required?

2020-07-10 Thread Matus UHLAR - fantomas
was whether the A record is needed at zone apex. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only substitute for good manners

Re: issue of Amplification attack

2020-07-12 Thread Matus UHLAR - fantomas
: https://lists.isc.org/pipermail/bind-users/2020-July/103389.html I find it more readable. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R

Re: VS: A And Cname-record

2020-06-18 Thread Matus UHLAR - fantomas
can be used without checking with an authoritative server for other RR types. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fighting for p

Re: Question about Recommended stress test tools for bind.

2020-06-26 Thread Matus UHLAR - fantomas
that xml statistics are better than rndc stads, I admin that they are kind fo better solution, however, I haven't found anything better for cacti, that could process those than what we currently have: https://docs.cacti.net/usertemplate:host:bind9.7 snmp support would be great. -- Matus UHLAR

Re: Recursive Client Rate limiting in BIND applicable in forward mode

2020-06-19 Thread Matus UHLAR - fantomas
you mean client request _rate_ is too large? 2. why forward to 8.8.8.8 ? BIND can resolve by itself, it does not to forward to 8.8.8.8 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: your mail

2020-06-28 Thread Matus UHLAR - fantomas
elf, so it really only matters if 1.1.1.1 is not accessible from internet. }; So, in this configuration, the abc.com will be forward to 8.8.8.8 or 1.1.1.1? the latter. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addr

Re: Fwd: DNS Misconfiguration on- http://cyberia.net.sa/

2020-06-05 Thread Matus UHLAR - fantomas
hreaded>* *Find attached POC Video. * *Dear Team Waiting for your response and I want bounty(money) with an Appreciation letter for my work and effort which I have given for * *Thanks in advance * *Ejaz * -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NO

<    3   4   5   6   7   8   9   10   >