ISC BIND & Windows

2022-02-01 Thread jukka . pakkanen
Just read from the 9.18.0 release notes that Windows is not supported. Since don't remember reading expressly stated that Windows support would end with 9.16.x branch, inquiring if there is more information about future Windows compatibility available... is the plan to include support to

BIND 9.16.15 Windows x64 broken?

2021-05-06 Thread Jukka Pakkanen
What changed between Bind 9.16.13 and 9.16.15 Windows x64 binaries? 9.16.15 will not start at all in Server 2008 R2 Enterprise x64, 9.16.13 worked fine. Only get "The service is not responding to the control function" when trying to start the service. Tried this as an upgrade to the 9.16.13,

VS: VS: CNAME / TXT

2020-08-24 Thread Jukka Pakkanen
In their (mailgun) instructions to the client. And then the client wanted us to include those to his zone. CNAME of course is useful in general, but like I wrote, *here* it is not needed. Jukka On 23.08.20 09:59, Jukka Pakkanen wrote: >Yes, I think the whole CNAME is useless here any

VS: CNAME / TXT

2020-08-23 Thread Jukka Pakkanen
CNAME you end up with a CNAME mx and TXT at the same node in to the DNS tree and that is illegal. That is why you get the error "cname and other data". The mx and txt are the other data. On Sat, Aug 22, 2020, 8:19 PM Jukka Pakkanen mailto:jukka.pakka...@qnet.fi>> wrote: Cannot

VS: CNAME / TXT

2020-08-23 Thread Jukka Pakkanen
401 characters… so that’a another problem. Thx. Lähettäjä: Kyongseon West Lähetetty: 23. elokuuta 2020 3:16 Vastaanottaja: Jukka Pakkanen Kopio: bind-us...@isc.org Aihe: Re: CNAME / TXT How long is the character in txt line? If it’s longer than 255, it will show that exact error. Exact thing

CNAME / TXT

2020-08-22 Thread Jukka Pakkanen
Cannot figure out what is wrong here... must be something simple but after sitting in airplanes the last 40 hours and it's 2am... Only when I comment out the two lines in the end of the named.harriot, it goes through and BIND load the zone. With those two lines, get the following:

VS: Dumb Question is an A or AAAA record required?

2020-07-09 Thread Jukka Pakkanen
Many spammers send in addition to MX to A records, if available. Still, it is a good practice to not to publish an A record for the mail zone, if not specifically needed for something else. Of course if it points to somewhere else than the receiving SMTP server, not much harm done

VS: Dumb Question is an A or AAAA record required?

2020-07-09 Thread Jukka Pakkanen
Only CNAME is perfectly fine, except if you want the site work without the www-prefix like someone already pointed out. Of course there must be A record for that name where the cname points to somewhere, but I read the question that this is not your concern. Jukka -Alkuperäinen

VS: A And Cname-record

2020-06-17 Thread Jukka Pakkanen
Yes but before going to RFC details one should check the basic spelling and syntax first... -Alkuperäinen viesti- Lähettäjä: bind-users Puolesta Mark Andrews Lähetetty: 18. kesäkuuta 2020 0:27 Vastaanottaja: Bogdan-Stefan Rotariu Kopio: bind-users@lists.isc.org Aihe: Re: A And

VS: A And Cname-record

2020-06-17 Thread Jukka Pakkanen
Including the trailing dots… Lähettäjä: bind-users Puolesta Jukka Pakkanen Lähetetty: 17. kesäkuuta 2020 23:51 Vastaanottaja: Ejaz Ahmed ; bind-users@lists.isc.org Aihe: VS: A And Cname-record Check at least the spelling… Lähettäjä: bind-users mailto:bind-users-boun...@lists.isc.org

VS: A And Cname-record

2020-06-17 Thread Jukka Pakkanen
Check at least the spelling… Lähettäjä: bind-users Puolesta Ejaz Ahmed Lähetetty: 17. kesäkuuta 2020 23:44 Vastaanottaja: bind-users@lists.isc.org Aihe: A And Cname-record when i am trying to add A and CNAME record together for the same subdomain, getting an error as below, you all kind

VS: VS: DNS Misconfiguration on- http://cyberia.net.sa/

2020-06-05 Thread Jukka Pakkanen
remember using as a guideline to set up our first domains/zones. And from that, the setting was copied later on to all new domains too. Jukka -Alkuperäinen viesti- Lähettäjä: Tony Finch Lähetetty: 5. kesäkuuta 2020 16:09 Vastaanottaja: Jukka Pakkanen Kopio: Ondřej Surý ; bi

VS: DNS Misconfiguration on- http://cyberia.net.sa/

2020-06-05 Thread Jukka Pakkanen
Thx for the info, had missed this one and actually we have that minor misconfiguration too. Have had since 1995 when started our nameservers and never noticed... Jukka -Alkuperäinen viesti- Lähettäjä: Ondřej Surý Lähetetty: 5. kesäkuuta 2020 11:53 Vastaanottaja: Jukka Pakkanen Kopio

VS: DNS Misconfiguration on- http://cyberia.net.sa/

2020-06-05 Thread Jukka Pakkanen
Complete scam, ignore. Just check the “securityfocus” link, it’s fake too. Jukka Lähettäjä: bind-users Puolesta Ejaz Ahmed Lähetetty: 5. kesäkuuta 2020 10:55 Vastaanottaja: bind-users@lists.isc.org Aihe: Fwd: DNS Misconfiguration on- http://cyberia.net.sa/ Some one is is claiming that our

VS: Change DNSSEC algorithm and switch to use KASP

2020-04-25 Thread Jukka Pakkanen
I just did the same operation in our BIND servers, converted all DNSSEC enabled zones with different algorithms to KASP/dnssec-policy and ecdsa256/13. All I did was replaced the two lines in named.conf: inline-signing yes; auto-dnssec maintain; to dnssec-policy "ecdsa256"; And of

VS: 9.16.2 / DNSSEC / DS records

2020-04-16 Thread Jukka Pakkanen
Thanks! -Alkuperäinen viesti- Lähettäjä: Mark Andrews Lähetetty: 16. huhtikuuta 2020 2:30 Vastaanottaja: Jukka Pakkanen Kopio: bind-us...@isc.org Aihe: Re: 9.16.2 / DNSSEC / DS records > On 16 Apr 2020, at 09:21, Jukka Pakkanen wrote: > > Updating from 9.14.11

VS: 9.16.2 / DNSSEC / DS records

2020-04-15 Thread Jukka Pakkanen
And yet, after updating Gemtrade.fi to dnssec-policy, ZSK and KSK both "13", and updating the DS record at the .fi root, I still get: (algorithm 13 not supportedsignature verification failed) In Verisign DNSSEC verifier. Lähettäjä: bind-users Puolesta Jukka Pakkanen Lähetetty: 16.

9.16.2 / DNSSEC / DS records

2020-04-15 Thread Jukka Pakkanen
Updating from 9.14.11 to 9.16.2, and migrating existing signed zones to dnssec-policy, and have couple questions, probably quite trivial... We have signed zones with different key algorithms, now I want everything under the same ecdsa256 policy. I guess when the key algorithm changes, example

VS: Advice on balancing web traffic using geoip ACls

2020-02-24 Thread Jukka Pakkanen
Hi, at the download page the status of 9.16 is “Current-Stable” but it also states “only for testing & evalution, *not* recommended for production”? Can you confirm if the DNSSEC inline-signing problem (signing just stops sometimes, affects both 9.11 and 9.14 branch) is present in this or not?

VS: Bind 9.11.13 - inline re-signing stops

2020-02-19 Thread Jukka Pakkanen
Like reported earlier, this same behavior/problem occurs also in 9.14.x branch, hopefully the fix will be found quickly, it is quite disturbing problem. Jukka -Alkuperäinen viesti- Lähettäjä: bind-users Puolesta Ondrej Surý Lähetetty: 19. helmikuuta 2020 7:17 Vastaanottaja: Matthew

VS: Bind 9.11.13 - inline re-signing stops

2020-02-05 Thread Jukka Pakkanen
..except our problem is with the 9.14.9 version/branch. -Alkuperäinen viesti- Lähettäjä: Jukka Pakkanen Lähetetty: 5. helmikuuta 2020 23:52 Vastaanottaja: 'Matthew Richardson' ; bind-users@lists.isc.org Aihe: VS: Bind 9.11.13 - inline re-signing stops Maybe related to your earlier

VS: Bind 9.11.13 - inline re-signing stops

2020-02-05 Thread Jukka Pakkanen
Maybe related to your earlier reported problem, when signed zonedata is not updated after updates to the zone? And what I already read about 9.11.15, hopefully fixed there. Jukka -Alkuperäinen viesti- Lähettäjä: bind-users Puolesta Matthew Richardson Lähetetty: 5. helmikuuta 2020

VS: VL: DNSSEC zones not updated

2020-01-28 Thread Jukka Pakkanen
Same here See also https://serverfault.com/questions/897894/bind-is-not-resigning-dnssec-zone-after-zone-update-and-service-restart Ale On Thu 23/Jan/2020 09:57:02 +0100 Jukka Pakkanen wrote: > Yes, that worked. Also had to delete the .jnl, to prevent the "not exact" > er

receive_secure_serial: unchanged (why?)

2020-01-24 Thread Jukka Pakkanen
While sorting out this latest DNSSEC problem, autosign not autosigning, this other older *cosmetic* problem would be nice to have fixed too... Windows Event Viewer filling with these error messages, which I think are not actual errors, should be more like warnings or notifications. When the

receive_secure_serial: unchanged (why?)

2020-01-23 Thread Jukka Pakkanen
service is restarted, every signed zone gives this "error" message: Lähettäjä: bind-users Puolesta Jukka Pakkanen Lähetetty: 9. lokakuuta 2019 1:51 Vastaanottaja: bind-us...@isc.org Aihe: DNSSEC 9.14.6 error message Having these *error* messages in the syslog when restarting the service

VL: DNSSEC zones not updated

2020-01-23 Thread Jukka Pakkanen
Yes, that worked. Also had to delete the .jnl, to prevent the "not exact" error.. Jukka -Alkuperäinen viesti- Lähettäjä: Mark Andrews Lähetetty: 23. tammikuuta 2020 0:53 Vastaanottaja: Jukka Pakkanen Kopio: bind-us...@isc.org; Browne, Stuart Aihe: Re: DNSSEC zones n

Re: DNSSEC zones not updated

2020-01-22 Thread Jukka Pakkanen
i36> From: Browne, Stuart Sent: Thursday, January 23, 2020 12:14:29 AM To: Jukka Pakkanen ; bind-us...@isc.org Subject: RE: DNSSEC zones not updated Sadly, no ideas other than a shared experience. It's not just the Windows release nor is it just the 9.14 series of releases; we've been witn

VS: DNSSEC zones not updated

2020-01-22 Thread Jukka Pakkanen
Anyone, any ideas? Lähettäjä: bind-users Puolesta Jukka Pakkanen Lähetetty: 22. tammikuuta 2020 13:30 Vastaanottaja: bind-us...@isc.org Aihe: Re: DNSSEC zones not updated And we also get after a change and a reload the "secure_serial: not exact" error, of course because the s

Re: DNSSEC zones not updated

2020-01-22 Thread Jukka Pakkanen
dows 2019 server. And it is not only this domain/zone, but all of them. Get Outlook for Android<https://aka.ms/ghei36> From: Ondřej Surý Sent: Wednesday, January 22, 2020 1:08:22 PM To: Jukka Pakkanen Cc: bind-us...@isc.org Subject: Re: DNSSEC zones not upd

Re: DNSSEC zones not updated

2020-01-22 Thread Jukka Pakkanen
ary 22, 2020 1:08:22 PM To: Jukka Pakkanen Cc: bind-us...@isc.org Subject: Re: DNSSEC zones not updated Hi, did you try stopping BIND, removing journal files and then starting BIND again? If the signed copy of the zone got corrupted in the memory, you might be dumping the corrupted version on disk

Re: DNSSEC zones not updated

2020-01-22 Thread Jukka Pakkanen
12:56 To: Jukka Pakkanen Cc: bind-us...@isc.org Subject: Re: DNSSEC zones not updated Just a basic question, are you querying the master or a slave. If a slave, it could be the notify/transfer. Thanks Sten On 22 Jan 2020, at 12.11, Jukka Pakkanen mailto:jukka.pakka...@qnet.fi>> wrote:

DNSSEC zones not updated

2020-01-22 Thread Jukka Pakkanen
Running BIND 9.14.9 Windows. The zone data is not updated for some reason anymore, and same problem in all our signed zones. Example "gemtrade.fi": zone "gemtrade.fi" { type master; file "named.gemtrade"; inline-signing yes; auto-dnssec maintain; }; ; ;File:

VS: DNSSEC 9.14.6 error message

2019-10-25 Thread Jukka Pakkanen
- Lähettäjä: bind-users Puolesta Jukka Pakkanen Lähetetty: 9. lokakuuta 2019 16:36 Vastaanottaja: Tony Finch Kopio: bind-us...@isc.org Aihe: VS: DNSSEC 9.14.6 error message Yes I can stop and restart the "isc bind" service without problems and/or errors, only get this message in restart, i

VS: DNSSEC 9.14.6 error message

2019-10-09 Thread Jukka Pakkanen
t; in syslog. Jukka -Alkuperäinen viesti- Lähettäjä: Tony Finch Lähetetty: 9. lokakuuta 2019 13:34 Vastaanottaja: Jukka Pakkanen Kopio: bind-us...@isc.org Aihe: Re: DNSSEC 9.14.6 error message Jukka Pakkanen wrote: > Having these *error* messages in the syslog when restarting

DNSSEC 9.14.6 error message

2019-10-08 Thread Jukka Pakkanen
Having these *error* messages in the syslog when restarting the service... guess they are not too harmfull, but why exactly is this coming: zone qnet.fi/IN (signed): receive_secure_serial: unchanged Just have this zone signed, but similar behaviout with other zones too. BIND 9.14.6 (Win) Thx,

VS: DNSSEC basic information

2019-09-23 Thread Jukka Pakkanen
Already found out about https://ftp.isc.org/isc/dnssec-guide/html/dnssec-guide.html, and that example the dnssec-enable option is now on by default… but any usefull hints still gladly received  Jukka Lähettäjä: bind-users Puolesta Jukka Pakkanen Lähetetty: 23. syyskuuta 2019 22:17

DNSSEC basic information

2019-09-23 Thread Jukka Pakkanen
I am finally diging in to DNSSEC, updating out BIND 9.14.5 servers to support it, both resolving & signing, secure zone transfers etc. I just have read the DNSSEC Mastery by Michael W. Lucas from year 2013, and my question basically is, is this information from 6 years back still valid, or

RE: Strange DNS problem

2019-06-10 Thread Jukka Pakkanen
- From: Stephane Bortzmeyer Sent: 10. kesäkuuta 2019 20:01 To: Jukka Pakkanen Cc: c...@cam.ac.uk; bind-us...@isc.org Subject: Re: Strange DNS problem On Mon, Jun 10, 2019 at 05:43:02PM +, Jukka Pakkanen wrote a message of 58 lines which said: > Then, unfortunately our nameservers wo

RE: Strange DNS problem

2019-06-10 Thread Jukka Pakkanen
-Original Message- From: Chris Thompson On Behalf Of Chris Thompson Sent: 10. kesäkuuta 2019 17:30 To: Jukka Pakkanen Cc: bind-us...@isc.org Subject: Re: Strange DNS problem On Jun 10 2019, Jukka Pakkanen wrote: >We have a strange problem related to DNS services, maybe someone h

RE: Strange DNS problem

2019-06-10 Thread Jukka Pakkanen
-Original Message- From: Chris Thompson On Behalf Of Chris Thompson Sent: 10. kesäkuuta 2019 17:30 To: Jukka Pakkanen Cc: bind-us...@isc.org Subject: Re: Strange DNS problem On Jun 10 2019, Jukka Pakkanen wrote: >We have a strange problem related to DNS services, maybe someone h

Strange DNS problem

2019-06-10 Thread Jukka Pakkanen
quiring their servers directly by servers IP addresses. Their NS records in the fi-root look little suspicious, like some of the servers lacked glue records, but not sure about that. Jukka Pakkanen Q-Net Oy ___ Please visit https://lists.isc.org/mailma

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
.1 of the RFC1035, where it is stated that "code 2 = server failure", and this should prove that our servers are not working because they got "server failure" error ;-) Jukka -Original Message- From: Tony Finch [mailto:d...@dotat.at] Sent: keskiviikko 26. syyskuuta 2

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
[mailto:bind-users-boun...@lists.isc.org] On Behalf Of Jukka Pakkanen Sent: keskiviikko 26. syyskuuta 2018 11.55 To: bind-users@lists.isc.org Subject: RE: BIND DNS problem (?) Started logging named now, but don't see much debug information with these logging settings: logging { category lame

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
94 client @01F51768CA50 62.142.220.9#47990 (73cb7fd0d8c8b44cd6e741d6eed0e612.smg.ultra.brightmail.com): query failed (SERVFAIL) for 73cb7fd0d8c8b44cd6e741d6eed0e612.smg.ultra.brightmail.com/IN/TXT at ..\query.c:10692 ... From: bind-users [mailto:bind-users-boun...@lists.isc.org] On B

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
.com/IN/TXT at ..\query.c:10692 From: Jukka Pakkanen Sent: keskiviikko 26. syyskuuta 2018 10.17 To: 'bind-users@lists.isc.org' Subject: RE: BIND DNS problem (?) Updated the pic, should be readable now... posting the pcap later. Jukka From: bind-users [mailto:bind-users-boun...@lists.isc.org] O

RE: BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
in to see anything. Please post a better screenshot or better yet post the .pcap itself for download and review. John From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Jukka Pakkanen Sent: Wednesday, September 26, 2018 2:46 AM To: bind-users@lists.isc.org<mailto:b

BIND DNS problem (?)

2018-09-26 Thread Jukka Pakkanen
We are running a couple of Symantec SMG servers, and their DNS clients are configured to use your BIND 9.12.2 DNS servers. In both SMG servers we get the same DNS "server failure" error from all our DNS servers when they do some TXT queries to SMG: http://www.qnet.fi/jp/dns.png (sorry for the

RE: Weird ping/traceroute proxying effect

2015-03-18 Thread Jukka Pakkanen
Are you using IP addresses or domain names when testing? If it works with IP address, but not with names, the sec. DNS server is lacking proper DNS services itself. -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of The

Re: Resolve only authoritative domain for internet/public addresses

2012-07-08 Thread Jukka Pakkanen
Why not just: acl X {A; B, C; ...; }; options { ... allow-query { any; }; allow-recursion { X; }; ...}; Jukka 8.7.2012 11:24, Phil Mayers kirjoitti: On 07/08/2012 07:15 AM, Mr BeEye wrote: Hello all. Let's have a finite list of IPv4 (private and public) addresses, e.g. {A, B, C,

Re: forwarding @ to a different domain?

2012-01-08 Thread Jukka Pakkanen
www in cname mydomain.myshopify.com. mydomain.com. in cname mydomain.myshopify.com. Is this what you are looking for? 8.1.2012 17:48, enigmedia kirjoitti: Hi All: I have a situation where I need to forward requests for mydomain.com and www.mydomain.com to a third party:

Re: forwarding @ to a different domain?

2012-01-08 Thread Jukka Pakkanen
8.1.2012 19:02, enigmedia (onl) kirjoitti: On Sun, 08 Jan 2012 20:00:07 +0200 Jukka Pakkanen jukka.pakka...@qnet.fi wrote www in cname mydomain.myshopify.com. mydomain.com. in cname mydomain.myshopify.com. Is this what you are looking for? Yes, but I thought you couldn't use a cname

Re: forwarding @ to a different domain?

2012-01-08 Thread Jukka Pakkanen
8.1.2012 20:46, Jukka Pakkanen kirjoitti: 8.1.2012 19:02, enigmedia (onl) kirjoitti: On Sun, 08 Jan 2012 20:00:07 +0200 Jukka Pakkanen jukka.pakka...@qnet.fi wrote www in cname mydomain.myshopify.com. mydomain.com. in cname mydomain.myshopify.com. Is this what you are looking for? Yes

Re: CNAME or A record?

2011-09-28 Thread Jukka Pakkanen
I think it's splitting hair but cname might be a bit more efficient. At least in the webserver end. In practise, I don't think there's a real difference. You can choose which ever feels better :) Jukka 28.9.2011 17:36, feralert kirjoitti: Thanks Jeff, But I really only wrote that as an

Re: CNAME or A record?

2011-09-28 Thread Jukka Pakkanen
Webserver still has to get the request, so one way or the other is required anyway :) 28.9.2011 17:43, ?? kirjoitti: this is the stuff what should be done by webserver rather than by DNS. i,e, Apache rewrite will do that. ? 2011-9-28 ??10:29,feralert feral...@gmail.com

9.8.1b3 windows binary

2011-07-16 Thread Jukka Pakkanen
The link in the download page seems to point to b2... Jukka ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org

Re: 9.8.1b3 windows binary

2011-07-16 Thread Jukka Pakkanen
16.7.2011 21:37, Evan Hunt kirjoitti: The link in the download page seems to point to b2... Whoops. Thanks, we'll get that fixed. Meantime, you can use the direct ftp URL: ftp://ftp.isc.org/isc/bind9/9.8.1b3/BIND9.8.1b3.zip Yeah figured the correct address and just in the process of

9.8.0 in 2008 R2 x64 server

2011-04-05 Thread Jukka Pakkanen
I'm moving one of our DNS servers (Win 2003 R2, v9.7.0) to a new 2008 R2 x64 server. After installing v9.8.0 I copied the /etc directory subdirectories, the named user has full rights in relevant directories and log on as a service rights... still I get the following error in eventviewer

Re: more flexible serial number handling in dnssec-signzone

2010-10-15 Thread Jukka Pakkanen
15.10.2010 20:54, Niobos kirjoitti: What's the advantage of using a date anyway? I too can see when a zone was last edited, even down to the second, by watching the RRSIG(SOA) timing. Time usually goes to one direction only, forward... so using date/time makes sure you are always

Re: new webserver ip

2010-08-03 Thread Jukka Pakkanen
3.8.2010 15:07, dhottin...@harrisonburg.k12.va.us kirjoitti: My employer decided to host our website on another server off-site. My problem is getting our dns to point from our old server to the new. Currently we own all the ip's and host our own website. Here is the zone file for

9.7.1-P1 ISC error 54

2010-08-01 Thread Jukka Pakkanen
Lately have seen in our 9.7.1-P1 server following errors: SOCKET_RECV: Windows error code: 1236, returning ISC error 54 And this warning: *** POKED TIMER *** Browsing the net told that this is/was a a common problem to even earlier Bind 9.x.x versions, but couldn't find any explanation or

Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
Doing first time the RFC 2317 style subnet reverse DNS, and have a problem with recursion. When doing a query like dig @ns1.qnet.fi -x 62.142.217.200 is succeeds from the local network, but outside I get recursion requested but not available. Our /24 reverse zones work fine, the server knows

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 11:29, Phil Mayers kirjoitti: On 07/29/2010 08:58 AM, Jukka Pakkanen wrote: Doing first time the RFC 2317 style subnet reverse DNS, and have a problem with recursion. When doing a query like dig @ns1.qnet.fi -x 62.142.217.200 is succeeds from the local network, but outside I get

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 13:45, Phil Mayers kirjoitti: On 29/07/10 10:00, Jukka Pakkanen wrote: 29.7.2010 11:29, Phil Mayers kirjoitti: On 07/29/2010 08:58 AM, Jukka Pakkanen wrote: Doing first time the RFC 2317 style subnet reverse DNS, and have a problem with recursion. When doing a query like dig @ns1

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 14:23, Mark Andrews kirjoitti: In message4c5134af.2080...@qnet.fi, Jukka Pakkanen writes: Doing first time the RFC 2317 style subnet reverse DNS, and have a problem with recursion. When doing a query like dig @ns1.qnet.fi -x 62.142.217.200 is succeeds from the local network

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 14:26, Niobos kirjoitti: On 2010-07-29 09:58, Jukka Pakkanen wrote Recursion is only allowed for the local networks, but why the server thinks recursion is needed in the first place? Because it is: dig -x looks for 200.217.142.62.in-addr.arpa. Your server is not a master

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 14:50, Phil Mayers kirjoitti: On 29/07/10 12:34, Jukka Pakkanen wrote: 29.7.2010 14:23, Mark Andrews kirjoitti: In message4c5134af.2080...@qnet.fi, Jukka Pakkanen writes: Doing first time the RFC 2317 style subnet reverse DNS, and have a problem with recursion. When doing a query

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 15:10, Mark Andrews kirjoitti: In message4c516756.5060...@qnet.fi, Jukka Pakkanen writes: 29.7.2010 14:23, Mark Andrews kirjoitti: In message4c5134af.2080...@qnet.fi, Jukka Pakkanen writes: Doing first time the RFC 2317 style subnet reverse DNS, and have a problem

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
...@qnet.fi Content-Type: text/plain; charset=ISO-8859-1; format=flowed 29.7.2010 14:26, Niobos kirjoitti: On 2010-07-29 09:58, Jukka Pakkanen wrote Recursion is only allowed for the local networks, but why the server thinks recursion is needed in the first place? Because it is: dig -x

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 15:21, Mark Andrews kirjoitti: Yeah, this makes sense. But my question still is, what is wrong in our setup, !!! NOTHING Well, then everything is good and I can go to my vacation... hopefully the clients whose IP addresses

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 15:43, Jukka Pakkanen kirjoitti: Please everybody just forget the 62.142.220.0/24 network and 62.142.220.5 address, the problem is not about them. It was just to inform that our servers are doing regular /24 reverse DNS just fine. The problem is we are trying to set up

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 16:00, Mark Andrews kirjoitti: Sorry about using 5 instead of something from 128 to 255 in the examples. That said there is nothing wrong here. Now I can agree :) However earlier our servers only answered to the local queries about those IP addresses, started working during

Re: Subnet reverse delagation, RFC 2317

2010-07-29 Thread Jukka Pakkanen
29.7.2010 17:06, Niobos kirjoitti: On 2010-07-29 15:00, Jukka Pakkanen wrote: Anyway we also have 62.142.217.64/27 IP network (you know what I mean) which should be delegated to our servers, but that still doesn't work. But it's probably a delegation problem. From my point of view

Re: MX and A

2010-04-11 Thread Jukka Pakkanen
Sounds like a problem with your smtp servers rather than dns. Setting up the A record for the domain should have no effect for the email delivery in properly configured system. What mechanism those smtp servers use to deliever the message to the clients email server, and have you checked the

Re: Bind slave to Windows 2008 AD/DNS

2009-12-08 Thread Jukka Pakkanen
Chris Buxton kirjoitti: On Dec 7, 2009, at 2:47 PM, Jukka Pakkanen wrote: I have out Bind servers running as slaves to Windows 2008 DNS server, and it's working fine as far as I can see (except that the slaves after a period of times lose the data and never update it unless restart

Bind slave to Windows 2008 AD/DNS

2009-12-07 Thread Jukka Pakkanen
I have out Bind servers running as slaves to Windows 2008 DNS server, and it's working fine as far as I can see (except that the slaves after a period of times lose the data and never update it unless restart the Bind process, but that's another matter) but browsing the web I noticed there

Re: Non English Domain names

2009-11-18 Thread Jukka Pakkanen
Yeah, no problems with scandinavian letters either. http://en.wikipedia.org/wiki/Punycode Sener ATAS kirjoitti: Hi, We use bind with turkish characters. And it works perfectly. for *www.bü.edu.tr* you must edit your zone like *www.xn--b-eha.edu.tr *Alans wrote: Hi, I know this is a

RE: Bind sometimes SERVFAIL

2009-11-11 Thread Jukka Pakkanen
Hello, My Internet ISP give two nameservers address. But when I'm asking those two servers sometimes I get: [r...@linux ~]# host d.yimg.com ns.my.isp Using domain server: Name: ns.my.isp Address: ns.my.isp#53 Aliases: Host d.yimg.com not found: 2(SERVFAIL) I just saw the same

RE: bind configuration help

2009-11-11 Thread Jukka Pakkanen
Sorry, but could You specify more accurately what is bad ? This is my first bind configuration, so probably I've made some mistakes, but I'd like to do it the right way in the end.:) On Tue, Nov 10, 2009 at 11:19 PM, Laurent CARON lca...@lncsa.com wrote: allow-recursion { any; }; bad

RE: bind configuration help

2009-11-11 Thread Jukka Pakkanen
From: Holger Honert [mailto:holger.hon...@signal-iduna.org] .. *Please be carefull when quoting, this was not me: Jukka Pakkanen schrieb: Sorry, but could You specify more accurately what is bad ? This is my first bind configuration, so probably I've made some mistakes, but I'd

Re: Slave to Win2003 DNS

2009-11-02 Thread Jukka Pakkanen
bsfin...@anl.gov kirjoitti: Jukka Pakkanen jukka.pakka...@qnet.fi wrote: Our Bind 9.6.1-P1 Windows servers are slaves to a Windows 2003 DNS server, zone company.local. For some reason t he slaves don't update the zone unless I restart the BIND service in the server, and after a while

Re: Slave to Win2003 DNS

2009-11-01 Thread Jukka Pakkanen
Matus UHLAR - fantomas kirjoitti: On 31.10.09 12:07, Jukka Pakkanen wrote: Our Bind 9.6.1-P1 Windows servers are slaves to a Windows 2003 DNS server, zone company.local. For some reason the slaves don't update the zone unless I restart the BIND service in the server, and after a while

Slave to Win2003 DNS

2009-10-31 Thread Jukka Pakkanen
Our Bind 9.6.1-P1 Windows servers are slaves to a Windows 2003 DNS server, zone company.local. For some reason the slaves don't update the zone unless I restart the BIND service in the server, and after a while, fail to respond to queries. Example, after a couple of days since the last

Re: [SPAM] Win2k and bind

2009-07-29 Thread Jukka Pakkanen
Unfortunately W2K was dropped a while ago, no safe version available for it. I know this is a very lame question, But I have been out of the Bind loop for a number of years ( yes I went over to the dark side ...MS DNS) but I want to come back. My question is this I have win2K servers what

Re: weight for RR

2009-06-04 Thread Jukka Pakkanen
Scott Haneda wrote: Maybe cheat with round robin? Add 3 copies of one record and 1 of the other. That should give you 75/25 roughly. BIND won't let you do that, it'll throw away the duplicates when it loads the zone. You need some other piece of software or hardware that can do that (insert

Re: What are these entries in the log file - query: . IN NS +?

2009-01-28 Thread Jukka Pakkanen
viestissä:p3evn4t6r9spme6ardiqbohjvlt99vt...@4ax.com... Jukka Pakkanen jukka.pakka...@qnet.fi wrote: There are many free third party firewall packages that can be run in Window= s = 2003 Server, we use the Net Firewall. Do you have a URL? I found http://www.ntkernel.com/wp.php?id=18 but it's not free

Re: What are these entries in the log file - query: . IN NS +?

2009-01-27 Thread Jukka Pakkanen
Tony Toews [MVP] tto...@telusplanet.net kirjoitti viestissä:p2vsn4leohtc8dm4a7m8rt4g6d4kem2...@4ax.com... Noel Butler noel.but...@ausics.net wrote: Surely windows can block access to an inbound IP request from some IP to local udp port 53 ? Not the firewall software built into Windows 2003

Re: Bind 9.6.0p1- Windows - The service did not respond to the startor control request in a timely fashion.

2009-01-13 Thread Jukka Pakkanen
Chiesa Stefano wrote: Hi all. Maybe it's not a new issue, but... I have a Windows 2003 SP2 with a 9.4.2 release that worked fine for years. Today I wanted to upgrade my release to 9.6. I installed it but when I try to start the service the system says: Event Type: Error Event Source: Service

RE: Bind 9.6.0p1- Windows - The service did not respond to the startor control request in a timely fashion.

2009-01-13 Thread Jukka Pakkanen
Jukka Pakkanen wrote: Chiesa Stefano wrote: Hi all. Maybe it's not a new issue, but... I have a Windows 2003 SP2 with a 9.4.2 release that worked fine for years. Today I wanted to upgrade my release to 9.6. I installed it but when I try to start the service the system says: Event Type

ISC BIND Windows?

2008-12-15 Thread Jukka Pakkanen
Sorry I've lost track of the different versions, which works in Windows and which don't. So... what is the latest version, working in W2K3? And Is W2K still abandoned? ___ bind-users mailing list bind-users@lists.isc.org