BIND with RPZ - CPU Affinity

2013-08-30 Thread Arie Lendra Putra
All,

 

Recently we put live some DNS Servers, 

 

The spec: 

2x Xeon (total seen by OS 24CPU)

16GB RAM
Ubuntu Server 12.04

 

We test limited number RPZ list BIND 9.8.1 (came with Ubuntu 12.04), and put
it on the live network, the result is OK, all load is shared among 24 CPU,
@10% usage

Then in response to BIND Security Advisory (exploit), we upgraded it to 9.8.
5-P2, and we increase  to RPZ list to a huge list (1,3M blacklist)

 

But now the CPU load is seem to focus only on CPU0 (40%), and remaining CPU
(1-23) only around 2%

 

Any idea what may seems to be the problem, 

 

 

Best Regards,

 

Arie Lendra Putra 

陈维文

Description: Calligraphy

--

Together is a beautiful word,

Coming together is the Beginning, Keeping together is Progress

Thinking together is Unity, Working together is Success

 

image001.png___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Some Server not Resolving certain address

2013-04-08 Thread Arie Lendra Putra
Hi,

 

I need some information /  suggestion regarding problem I’m having in my
DNS Servers,

We have 10 DNS servers, which all using BIND, all the server acting as
recursive  (caching) DNS server only, no authoritative records at all,

 

The problem I’m having is some of our customer cannot resolve certain
domain name, (e.g. www.positivebrain.asia and www.virtucamp.com), 4 out of
10 servers can resolve the domain successfully, but the remaining is not
success. All server virtually the same configuration,

 

Any idea what seem to be the culprit? Is it the root dns populate issue or
something else? Is there a way to force DNS server to update from root?

 

Thank You for any support given.

 

 

Best Regards,

 

Arie Lendra Putra 

陈维文

Description:
http://www.chinese-tools.com/jdd/public/callitext/2027048691360925224.png

--

Together is a beautiful word,

Coming together is the Beginning, Keeping together is Progress

Thinking together is Unity, Working together is Success

 

image001.png___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Monitoring BIND

2013-02-15 Thread Arie Lendra. Putra
Hi,

 

Let me introduce myself, 

My name is Arie L. Putra, I’m a data network engineer at a EVDO operator.

 

We are using BIND 9.3.6 ( a bit old yes), for our caching-only name server, we 
are not maintaining authoritatives. 

 

We are not monitoring our DNS Server using:

1. Cacti (for traffic, cpu, mem, etc)

2. Munin for Stats

 

Do you have any recommendation for monitoring bind response time from a 
customer test node (a windows box)

On linux we could set up a dig script that provide response time in 
millisecond-ftp’ed to our server then graph it with RRDtool.

 

Any recommendation for windows env.?

 

Best Regards,

 

Arie Lendra Putra 

陈维文

 

--

Together is a beautiful word,

Coming together is the Beginning, Keeping together is Progress

Thinking together is Unity, Working together is Success

si↑ ,n

 

image001.png___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users