Re: 9.18 BIND not iterated over all authoritative nameservers

2023-10-27 Thread Lyle Giese
server and responsible party records are not resolvable. Maybe someone with more knowledge of DNS and the use of .local. domain name can shed some light on this. Lyle Giese On 10/27/23 10:36, Michael Martinell via bind-users wrote: Hello, At this point I am hoping that somebody might have

Re: Reverse lookups not working when Internet connection failed.

2022-11-04 Thread Lyle Giese
or is not there, a recursive only server will fail to give you the answer you seek. That is very dependent on your internal dns setup and the type of dns server you are querying. Lyle Giese On 11/4/22 11:07, David Carvalho via bind-users wrote: Thanks for the replies. My reverse zone file

Re: Stopping ddos

2022-08-04 Thread Lyle Giese
source address. Lyle On 8/3/22 08:30, Robert Moskowitz wrote: Thanks.  I will look into this. On 8/3/22 07:47, Victor Johansson via bind-users wrote: Hey, I just want to add that there is a better way to do this in iptables with hashlimit. The normal rate limit in iptables is too crude. Below

Re: Need Help with BIND9

2021-06-15 Thread Lyle Giese
Yep, that fixed it. Lyle On 6/15/21 2:23 PM, techli...@phpcoderusa.com wrote: Thank you for your help!!  The zone file is the one I tool from Plesk when I had keiththewebguy.com parked there.  All I did was change the IP addresses. I assume what you want me to do is add keiththewebguy.com

Re: Need Help with BIND9

2021-06-15 Thread Lyle Giese
.keiththewebguy.com not ns1. ). Lyle Giese LCR Computer Services, Inc. On 6/15/21 9:04 AM, techli...@phpcoderusa.com wrote: On 2021-06-15 01:38, Reindl Harald wrote: Am 15.06.21 um 10:31 schrieb Reindl Harald: Am 14.06.21 um 22:37 schrieb techli...@phpcoderusa.com: keiththewebguy.com [1

Re: Bind 9.10 recursion issues

2020-12-04 Thread Lyle Giese
Why are you using forwarders?  These cloudflare servers are not authoritive for cat.com and don't seem to be open resolvers either. Lyle Giese LCR Computer Services, Inc. On 12/4/20 12:48 PM, Wade Blackwell wrote: Good morning from the West Coast,                 It’s been a while since

Re: RRL outcome on legitimate traffic...

2020-12-01 Thread Lyle Giese
Probably best to ask Paul Vixie for confirmation. I had implemented RRL when it was still an addon and that was what was documented back then. On 12/1/20 10:15 AM, Karl Pielorz wrote: --On 1 December 2020 at 08:24:50 -0600 Lyle Giese wrote: You need to look at the reply named sends

Re: RRL outcome on legitimate traffic...

2020-12-01 Thread Lyle Giese
not blindly just drop traffic. Lyle Giese LCR Computer Services, Inc. On 12/1/20 4:58 AM, Karl Pielorz wrote: Hi all, So there's been quite a thread - that originally started as "Bind stats - denied queries" - and morphed into a whole discussion on spoofed UDP, logging, RRL et

Re: Bind stats - denied queries?

2020-11-30 Thread Lyle Giese
Be careful 'rejecting' these outright.  These queries are UDP traffic(not TCP) and the source address is easily forged.  RRL is the correct way to limit these. Lyle Giese LCR Computer Services, Inc. On 11/30/20 4:12 AM, Marc Roos wrote: Are newer version of bind still logging like

Re: conflicting subdomain delegation

2018-11-13 Thread Lyle Giese
recursive only server(other than host1), I would expect the same behavior as the +trace result. so I think the answer is dependant on how your bind9 resolver is configured. Lyle Giese ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: [SOLVED] My Exchange server is now able to send email to httpd.apache.org domain after I added SPF TXT record to my DNS server

2018-08-14 Thread Lyle Giese
The reverse lookup for 118.189.211.120 does not match your HELO greeting and does not match the A record for exchange.teo-en-ming.com.  Get your upstream ISP to fix that. Lyle Giese LCR Computer Services, Inc. On 8/13/2018 8:28 PM, Turritopsis Dohrnii Teo En Ming wrote: Good morning from

Re: SOA settings

2018-02-01 Thread Lyle
Bind does default to seconds. However this is not the SOA record. Lyle On 02/01/18 18:08, lbutlr wrote: I am looking at a config file and seeing: 2017112100 ; serial 1H ; refresh 15 ; retry 1w ; expire 1H ; minimum Is that 15 15 seconds? I'm guess ion it should be 15m

Re: Organization IP address is getting redirected to a website which does not belong to the organization.

2016-09-17 Thread Lyle
6.142.7.113 tcp port 80. It's issuing a 302 redirect to http://www.watcheezy.com at ip address 37.187.76.95. That host is issuing a 301 redirect to http://us.watcheezy.com at 37.187.76.95. Lyle Giese LCR Computer Services, Inc. ___ Ple

Re: rndc on local host: need named running?

2016-08-27 Thread Lyle
Use any in the allow stanza. On 08/27/16 19:54, Tom Browder wrote: On Saturday, August 27, 2016, Lyle <l...@lcrcomputer.net <mailto:l...@lcrcomputer.net>> wrote: On 08/27/16 10:54, Tom Browder wrote: https://calomel.org/dynamic_dns_ddns.htmlMy plan is to have two

Re: rndc on local host: need named running?

2016-08-27 Thread Lyle
On 08/27/16 10:54, Tom Browder wrote: My plan is to have two remote, authoritative name servers (master and slave) for my owned domains. I would like to use rndc to control them from my local host. A couple of questions: 1. Does named need to be running on the local host? No. 2. Can I

Re: Allowable reverse mapping zone file names

2016-08-27 Thread Lyle
zones to the end user. In that case, you have to ask them to insert the records you think necessary including your mail server's host name. Lyle Giese LCR Computer Services, Inc. On 08/27/16 10:47, Tom Browder wrote: I do not control 3-octet networks but need reverse mapping for my mail server

Re: How to Fix Reverse DNS?

2015-09-22 Thread Lyle Giese
lookup for you. Lyle Giese LCR Computer Services, Inc. On 9/22/2015 2:08 PM, Ron Wingfield wrote: RE: BIND v9.10.2 I have recently converted from a "legacy" DSL service to AT's U-verse . . .has been a painful experience. Heretofore, the following from /var/named/named.conf

Re: Installing bind is not very clear for me

2015-09-03 Thread Lyle Giese
net facing applications. Lyle Giese ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: DIG Info Request

2015-02-03 Thread Lyle Giese
If I remember right, DIG does not know the root servers and asks the local host to retrieve that information and a server at 172.27.254.11(which is RFC 1918 address space) gave you that answer. Is your machine/shop setup with private root servers? Lyle On 2/3/2015 12:50 PM, Linux Addict

Re: DIG Info Request

2015-02-03 Thread Lyle Giese
172.27.254.11 is giving you that info with the .new name servers. You need to ask whomever manages that server. Look at this line from your +trace output: Received 405 bytes from 172.27.254.11#53(172.27.254.11) in 1 ms Lyle On 2/3/2015 1:13 PM, Linux Addict wrote: Additional info - general

Re: Why the heck my NS are not working

2014-07-20 Thread Lyle Giese
post the domain name so we can look from out here. Is the name server on a public ip address and your firewall allowing udp tcp port 53 access to talk to named? Lyle On 07/20/14 02:21, Blason R wrote: Hi Guys, Though it may not relevant with BIND but I need help with NS servers which

Re: Zone transfer doesn't work when I set allow-update statement

2014-04-25 Thread Lyle Giese
Allow-update makes the zone a dynamic update zone. You have to stop hand editing the zone file. Use nsupdate to make changes to the zone. Lyle Giese LCR Computer Services, Inc. On 04/25/14 15:03, Jeronimo L. Cabral wrote: Dear, I'm using Bind 9.8.4 with a master / slave scenario. Zone

Re: Zone transfer doesn't work when I set allow-update statement

2014-04-25 Thread Lyle Giese
How are you checking for updated info from the master? I recommend dig @ip address of master test.company.com.ar Lyle Giese LCR Computer Services, Inc. On 04/25/14 15:29, Jeronimo L. Cabral wrote: Thanks a lot, but using the allow-update statement, I use nsupdate in order to add a new record

Re: d root server

2013-08-20 Thread Lyle Giese
Your bind code is old and has the old info in it. D root changed it's ip address. Bind has a built-in hints file, in case you don't setup one and it probably has the old ip address for the D root. http://blog.icann.org/2012/12/d-root/ Lyle Giese LCR Computer Services, Inc. On 08/20/13 15

Re: d root server

2013-08-20 Thread Lyle Giese
Have you read the source code for these versions of BIND and examined the set of HINTS that are internal to the code inside BIND? These are loaded before any external HINTS file is loaded up. Lyle On 08/20/13 16:37, rohan.he...@cwjamaica.com wrote: Lyle, Version 9.8.4-P1 is also affected

broken ISP in china

2013-02-18 Thread Lyle Giese
. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: [mailop] broken ISP in china

2013-02-18 Thread Lyle Giese
On 02/18/13 19:02, Tony Finch wrote: Lyle Giese l...@lcrcomputer.net wrote: Recently I moved this domain(lcrcomputer.net) to a registrar that suports DNSSEC and inserted the DS record for this domain. Was it signed before this point? I am wondering if this is a DNS response size problem

Re: lame-servers: error (FORMERR) resolving [something]

2013-01-11 Thread Lyle Giese
On 01/11/13 03:05, Daniele wrote: Port 53 is open, I can also telnet it from another box in the same network. Now I think the problem can be on the packets size, because I'm trying every solution but nothing works. 2013/1/9 Lyle Giese l...@lcrcomputer.net mailto:l...@lcrcomputer.net

Re: lame-servers: error (FORMERR) resolving [something]

2013-01-09 Thread Lyle Giese
that a recursive name server does. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: First usage of BIND9

2012-11-24 Thread Lyle Giese
for a caching-only name server, which is what you are asking for. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: query (cache) 'domain.com/AAAA/IN' denied

2012-10-10 Thread Lyle Giese
actually have another machine that has bind 9.4.2 and it works as desired without all this options. both machines a meant to be authoritative for domain.com... anything else i can try? thanks... -- Arni - Original Message - From: kalin ka...@el.net To: Lyle Giese l

Re: Root hints updates

2012-09-06 Thread Lyle Giese
. It's only at ftp.internic.net. This page has a pointer to root hints file(via FTP) that does not work either. The http version shows the above mistake. It's not available at rs.internic.net. http://www.iana.org/domains/root/files Lyle Giese LCR Computer Services, Inc

Re: Corrupt zone transfer

2012-06-29 Thread Lyle Giese
format. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

No valid trust anchors for '.' - solved

2012-06-10 Thread Lyle Giese
issue, I did not go back to the logs and look at the first boot error messages and focused on the last restart of named set of messages. Lyle Giese LCR Computer Services, Inc. Related error messages: Jun 9 22:29:21 ns1a named[6252]: zone 78.0.10.in-addr.arpa/IN/chase: refresh: failure trying

Re: forwarders

2012-05-28 Thread Lyle Giese
seconds for msrv.cairosource.com. This low TTL makes it look like you have a dynamic ip address. Most RBL's require a minimium of 12 hrs and recommend 24 hour TTL on these two records. Lyle Giese LCR Computer Services, Inc. ___ Please visit https

Re: Host command timing out sporadically

2012-05-02 Thread Lyle Giese
to the point, dig gives up trying. But the use of dig +trace shows much more diagnostic information which points us to the real issue you have. Lyle Giese LCR Computer Services, Inc. On 05/02/12 16:36, Paul Marais wrote: Thanks Lyle, You're right - I started using the host command because

Re: Host command timing out sporadically

2012-05-02 Thread Lyle Giese
, the recursion setting in named is immaterial when doing dig +trace. Once dig gets the addresses of the root server, it stops asking your local copy of named and starts asking the root servers for itself and does not rely any further on named. Lyle On 05/02/12 18:59, Paul Marais wrote: I

Re: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread Lyle Giese
file on the local machine that contains... Or in your proxy server redirect www.google.com to nosslsearch.google.com DNS server software is not very supportive of doing this for good reasons. Lyle Giese LCR Computer Services, Inc. ___ Please visit

Re: Recursive queries fail after bind has been running for a few hours

2012-03-12 Thread Lyle Giese
seconds of preceeding logs missing when the query started? Lyle Giese LCR Computer Services, Inc. On 03/12/12 15:05, Mr X wrote: Hey there I'm having a bizarre issue with 9.7.3-P3-RedHat-9.7.3-8.P3.el6_2.2 - recursive queries stop functioning after bind has been running for a few hours. It's

Re: Master/slave configuration

2012-03-07 Thread Lyle Giese
On linux boxes, adding options rotate to the /etc/resolv.conf helps. Lyle Giese LCR Computer Services, Inc. On 03/07/12 06:54, Bostjan Skufca wrote: Problem is, most of client resolvers (not resolving nameservers, but resolvers on workstations etc) query first specified nameserver first

Re: CVE-2012-1033 (Ghost domain names) mitigation

2012-02-09 Thread Lyle Giese
thinking(and I could be quite wrong here) is that my server will cache a good verified answer and DNSSEC does not seem to help here. Please let me know where I am wrong here if I am. Lyle Giese LCR Computer Services, Inc. ___ Please visit https

Re: Name resolution issue on one domain

2012-01-12 Thread Lyle Giese
out the query. Lyle Giese LCR Computer Services, Inc. On 01/12/12 08:11, babu dheen wrote: Hi, I can see only below line in the logs which is no more useful. Actully i would like to find out where exactly DNS query is blocked during query process /*client 127.0.0.1#46547: view

Re: About root zones

2012-01-03 Thread Lyle Giese
for a specific use case and ISC is not into generating special builds for special or specific use cases unless you contract with them to build and maintain your special build of BIND. Lyle Giese LCR Computer Services, Inc. ___ Please visit https

Re: Subdomain Issue

2011-11-10 Thread Lyle Giese
example.com aINA203.39.45.20 bINA203.39.45.21 /\ *Tarak* * Where are your A records for your name servers, ns1.example.com, ns2,example.com and ns4.example.com? And please answer the question above, what does the named's log say when starting up? Lyle Giese

Re: Subdomain Issue

2011-11-10 Thread Lyle Giese
On 11/10/11 12:24, trm asn wrote: On Thu, Nov 10, 2011 at 8:28 PM, Lyle Giese l...@lcrcomputer.net mailto:l...@lcrcomputer.net wrote: On 11/09/11 15:59, trm asn wrote: On Wed, Nov 9, 2011 at 3:15 PM, Matus UHLAR - fantomas uh...@fantomas.sk mailto:uh...@fantomas.sk

Re: several master ip's for a slave zone

2011-11-05 Thread Lyle Giese
. The slaves actually ask for the SOA record from each Master when refreshing. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users

Re: DNSSEC and forward zones

2011-11-01 Thread Lyle Giese
situation. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Problems with nic.it

2011-09-20 Thread Lyle Giese
/listinfo/bind-users Just a quick question, have you registered your name servers with your domain registrar? nic.it may be looking for the necessary glue records. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman

Bug in Bind 9.8 or am I doing something wrong?

2011-09-06 Thread Lyle Giese
I doing something wrong? Thanks, Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: Bug in Bind 9.8 or am I doing something wrong?

2011-09-06 Thread Lyle Giese
On 9/6/2011 9:13 AM, Tony Finch wrote: Lyle Giesel...@lcrcomputer.net wrote: zone chaseprod.local{ type forward; forwarders {10.0.100.205;};}; This seemed to work until I added some stuff for DNSSEC to my named.conf. In order to forward a zone in the presence of DNSSEC

Re: Seemingly random ServFail issues on a caching server

2011-08-31 Thread Lyle Giese
, MD from here. They did have a hurricane go through there and I would not be surprised if traffic levels have been a bit high for the last few days. Lyle ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from

Re: DNS Caching Issue

2011-07-26 Thread Lyle Giese
, --Sathyan Simple ask both nameservers for the domain sin.gpi-g.com and you get different answers. They have serious DNS problems. Lyle Giese LCR Computer Services, Inc. dig @192.5.6.30 sin.gpi-g.com ; DiG 9.7.3 @192.5.6.30 sin.gpi-g.com ; (1 server found) ;; global options: +cmd ;; Got

Re: Bind time up.

2011-07-23 Thread Lyle Giese
On 07/23/11 09:33, Vbvbrj wrote: On 23.07.2011 17:24, Lyle Giese wrote: On 07/23/11 03:22, Vbvbrj wrote: Hello. I have a server at home, that runs Bind 9 dns and routes internal traffic to internet. Its working fine. When I'm out of home, I disconnect my home switch. In bind log appears

Re: Bind time up.

2011-07-23 Thread Lyle Giese
On 07/23/11 11:13, Vbvbrj wrote: On 23.07.2011 19:00, Lyle Giese wrote: On 07/23/11 09:33, Vbvbrj wrote: On 23.07.2011 17:24, Lyle Giese wrote: On 07/23/11 03:22, Vbvbrj wrote: Hello. I have a server at home, that runs Bind 9 dns and routes internal traffic to internet. Its working fine

Re: about the dig

2011-07-19 Thread Lyle Giese
in named.conf. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: DDNS propagation between views

2011-07-08 Thread Lyle Giese
zone files. You need to plan and it helps to read the FAQs at ISC about this. http://www.isc.org/faq/item/191 http://www.isc.org/faq/item/182 Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: DDNS propagation between views

2011-07-08 Thread Lyle Giese
patterns in order. Lyle ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: questions on the dig info

2011-07-08 Thread Lyle Giese
of www.qq.com) returns nothing for this zone's NS query? Misconfiguration of ns-tel1.qq.com or it's not allowed to give you that answer. Hard to tell from here. The view from here does not show ns-tel1.qq.com to be authorative for www.qq.com. Lyle Giese LCR Computer Services, Inc

Re: a death loop with DNS query

2011-07-06 Thread Lyle Giese
.com and ns2.dnsv5.com, you get four A records returned each. However at least from here and it appears from where you are doing the querys, these name servers are not responding. So Dig is just trying all A records returned. Lyle Giese LCR Computer Services, Inc

Re: Problem with name resolving

2011-07-02 Thread Lyle Giese
On 07/02/11 04:48, Markus Feldmann wrote: Am 01.07.2011 22:43, schrieb Lyle Giese: I don't know dyndns.com services that well. I don't know what they support or do not support directly. I added two Hosts at dyndns.org test-feldland.dyndns.org and feldland.dyndns.org both would have the same IP

Re: Problem with name resolving

2011-07-02 Thread Lyle Giese
On 07/02/11 04:37, Markus Feldmann wrote: Am 01.07.2011 22:43, schrieb Lyle Giese: On 07/01/11 14:13, Markus Feldmann wrote: Am 01.07.2011 18:35, schrieb Lyle Giese: You are right in that you only need one host at dyndns.org to update your ip address, but you want to have two different

Re: Problem with name resolving

2011-07-01 Thread Lyle Giese
for troubleshooting this issue. It would appear that you setup the dyndns client on your debian box to update feldland.dyndns.org. But how and where do you update the other two? www.feldland.dyndns.org and test.feldland.dyndns.org Or did you forget to create those at dyndns.org? Lyle Giese LCR

Re: about the reference

2011-07-01 Thread Lyle Giese
, the results will be unpredicatable and random. Sometimes it will work and sometimes it won't work. It's important that the glue records be correct. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind

Re: Problem with name resolving

2011-07-01 Thread Lyle Giese
On 07/01/11 08:50, Markus Feldmann wrote: Am 01.07.2011 14:51, schrieb Lyle Giese: Markus, To be sure, you know that nslookup and dig do NOT use the search parameter in /etc/resolv.conf. So when you do an nslookup or dig query, you have to use the fully qualified domain name(FQDN). PING uses

Re: Problem with name resolving

2011-07-01 Thread Lyle Giese
On 07/01/11 14:13, Markus Feldmann wrote: Am 01.07.2011 18:35, schrieb Lyle Giese: You are right in that you only need one host at dyndns.org to update your ip address, but you want to have two different websites. The proper way to do that is with CNAME entries pointing to the host you

Re: bind restart needed to reflect changes to dynamic zone in multiple views

2011-06-24 Thread Lyle Giese
rbldnsd. I have written perl scripts to periodicly pull a copy of the database and parse that into text files compatible with rbldnsd and move them into place. rbldnsd automagically reloads the updated zone files. Lyle Giese LCR Computer Services, Inc

Re: bind restart needed to reflect changes to dynamic zone in multiple views

2011-06-24 Thread Lyle Giese
On 06/24/11 09:21, Brian J. Murrell wrote: On 11-06-24 09:57 AM, Lyle Giese wrote: It's expected behavior in a way. Given your explanation, indeed. :-) You are probably making this change in the internal view and the internal named process knows about the change and reloads the zone

Re: How to Setup a Name Servers visible on Internet?

2011-06-21 Thread Lyle Giese
://lists.isc.org/mailman/listinfo/bind-users Try removing the wild card entry in the metropolitanbuntu.co.za and see if that clears this error. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: How to Setup a Name Servers visible on Internet?

2011-06-20 Thread Lyle Giese
On 06/20/11 12:31, Metropolitan College Eric Kom wrote: Maybe I'm still mix up somethings because after change the settings, the *grep named /etc/log/syslog* still showing errors: Jun 20 19:21:58 ns1 named[3178]: managed-keys-zone ./IN/internal: loading from master file

Re: Restoring BIND DNS configuration from TAR command

2011-06-19 Thread Lyle Giese
were partial to info over man. Try: info tar There is alot more information in the info pages than man pages for tar. Plus the original poster needs to learn how to use the command line a lot better. Lyle Giese LCR Computer Services, Inc. ___ Please

Re: nameserver registration

2011-06-18 Thread Lyle Giese
proper glue records are maintained for any/all name servers used with a domain registered with them. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: I can't resolve one domain: nhs.uk

2011-06-17 Thread Lyle Giese
be in China. (ns2.fengnet.com and ns1.zjinfo.gov.cn). If you are in fact doing this query from China, all bets are off for a successful query. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: forward name resolution OK, but reverse doesn't work ...

2011-06-17 Thread Lyle Giese
. Are you getting zone transfers from there? I question the need or a desire to have a copy of that zone on your dns server, let alone if you are getting a full zone from the F root. Lyle Giese LCR Computer Services, Inc. ___ Please visit https

Re: How to Setup a Name Servers visible on Internet?

2011-06-17 Thread Lyle Giese
an additional layer of confusion. Lyle Giese LCR Computer Services, Inc. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: How to improve bind caching dns server performance

2011-06-10 Thread Lyle Giese
the errors you see. There is nothing you can do to fix the errors you described. In addition, you should learn how to use dig +trace for troubleshooting these problems. Lyle ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org

Re: Problem resolving CNAME in BIND 9.8.0 and 9.8.0-P2

2011-06-10 Thread Lyle Giese
the +trace option. Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: BIND error: opcode: QUERY, status: SERVFAIL

2011-06-03 Thread Lyle Giese
server on this machine. Do you have UDP and TCP ports 53 open to this server? You need both open. Lyle Giese LCR Computer Services, Inc. On 06/03/11 02:04, kshitij mali wrote: Hello ALL Please help me toubleshoot this bind ISSUE I am facing intermetent problem with some domains

Re: IPv6 prefix length error

2011-04-28 Thread Lyle Giese
in the host OS. You have not specified the prefix length(compares to /24 for IPv4 cidr notation) in your network configuration for your IPv6 addresses. Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing list bind-users@lists.isc.org https

Re: [OT] does deliveragent must have a PTR RR

2011-01-31 Thread Lyle Giese
that this area at AOL has to offer or you will miss some important points, like that 12 hrs is considered the min TTL for A and PTR records for mail servers. Less than 12 hrs TTL on these records are considered by default indicators of dynamic IP addresses. Lyle Giese LCR Computer Services, Inc

Re: host unreachable. -- a bit more info

2011-01-10 Thread Lyle Giese
arlut.utexas.edu Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: host unreachable. -- a bit more info

2011-01-10 Thread Lyle Giese
in the firewalls between the two sites. BTW, zone transfers are done using TCP because of their size. Small queries try to use UDP first. This is starting to sound more like the master is not allowing your site to get a zone transfer. That is an ACL issue for the master site. Lyle Giese LCR Computer

Re: to route specific dns query to specific dns server

2010-12-29 Thread Lyle Giese
outside your internal network will know about the microsoft domain. The book has examples plus syntax and examples that will cover the rest of your questions. Lyle Giese LCR Computer Services, Inc. Riccardo Castellani wrote: Hopefully the microsoft domain is a name that is not availible

Re: about the zone file management

2010-11-29 Thread Lyle Giese
Or nsupdate Lyle Giese LCR Computer Services, Inc. philippe.simo...@swisscom.com wrote: Hi if i good understand your question maybe the answer is : rndc freeze / thaw Philippe -Original Message- From: bind-users-bounces+philippe.simonet=swisscom@lists.isc.org

Re: How does Yahoo/Google find unknown domains?

2010-11-09 Thread Lyle Giese
Konzack Despite how I feel about Yahoo's SLURP engine, it still honors robots.txt. Script kiddies don't. Lyle Giese LCR Computer Services, Inc. P.S. My last post on this. This is not DNS related. ___ bind-users mailing list bind-users

Re: How does Yahoo/Google find unknown domains?

2010-11-07 Thread Lyle Giese
in an index.html that redirects accidential visitors to my commerical business homepage. Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

dnsexperiment.net

2010-10-23 Thread Lyle Giese
. Lyle Giese LCR Computer Services, Inc. Oct 22 16:32:42 linux2 named[20883]: client 69.167.186.59#45185: view external: query (cache) 'ofw4blrqy4.cache.lab.dnsexperiment.net/A/IN' denied Oct 22 16:32:43 linux2 named[20883]: client 69.167.186.59#35522: view external: query (cache

Re: DNS Propagation

2010-10-14 Thread Lyle Giese
, but you do need to reply to the list and I sometimes forget as this list server does not put the list in as the from address and my reader does not pick that up. Lyle Giese LCR Computer Services, Inc. João Alberto Kuchnier wrote: Sorry about that. The domain is dataprom.com. ns1.dataprom.com

Re: DNS Propagation

2010-10-14 Thread Lyle Giese
, scroll down and under More Domain Options, click on Manage Name Servers. This is where you manage the glue records for your name servers. Lyle Giese LCR Computer Services, Inc. João Alberto Kuchnier wrote: Lyle, Domain registrar like Network Solutions? My domain account is set to ns1 and ns2

Re: DNS Propagation

2010-10-14 Thread Lyle Giese
me to fix this issues? João K. Google is your friend! Please use it. You have mistakes of some sort in your named.conf and/or your zone files. Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing list bind-users@lists.isc.org https

Re: Bind and blacklist IP file

2010-10-11 Thread Lyle Giese
Alans wrote: Hello, Is it possible for bind dns to check the queries, if the returned answer is existed in a file that contains blacklisted IPs then block it? One more thing, from where we can get/buy updated lists of categorized IPs/websites, like Gaming, Porn, Social...? Thanks, Alans

Re: Unable to query the nameserver

2010-10-05 Thread Lyle Giese
asking about ns1 or ns2.sharingcenter.de. Those queries appear to be returning a wild card entry of 80.92.66.130 for ns1 and ns2.sharingcenter.de. There is no name server answering at 80.92.66.130 and thus Eurodns reports that name server is not answering. Lyle Giese LCR Computer Services, Inc

Re: Unable to query the nameserver

2010-10-04 Thread Lyle Giese
, but we can not tell as you are not posting the real IP addresses. Even though the ip addresses involved are registered for web and dns services that should be availible to the world anyway. Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing

Re: installing on SLES 10sp3

2010-09-12 Thread Lyle Giese
Chris Buxton wrote: On Sep 9, 2010, at 5:02 PM, Lyle Giese wrote: wllarso wrote: I'm not any sort of Linux expert but this started my mind thinking. Take a look at the BIND FAQ, it comes with the sources. There are some Linux specific comments about file and directory permissions

Re: ipv6 implementation in an ipv4 camp

2010-09-10 Thread Lyle Giese
of good info at http://ipv6.he.net and at http://www.sixxs.net for getting a working IPv6 tunnel into their network and how to implement IPv6. Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing list bind-users@lists.isc.org https

Re: installing on SLES 10sp3

2010-09-09 Thread Lyle Giese
Lyle Giese wrote: I am not running named as named, but as root(no -u on command line). But in testng I did change the permissions on this directory to 777 with no change in behaviour and changed it back to 755. Lyle Giese LCR Computer Services, Inc. dhottin...@harrisonburg.k12.va.us wrote

Re: installing on SLES 10sp3

2010-09-09 Thread Lyle Giese
David Forrest wrote: On Thu, 9 Sep 2010, Lyle Giese wrote: I am trying to install bind 9.7.1-P2 from source on a SLES 10 SP3 server. When I run named from the command line, it runs, but fails to open and write any of the zone files it downloaded. named -c /etc/named.conf (yes I am

Re: installing on SLES 10sp3

2010-09-09 Thread Lyle Giese
David Forrest wrote: On Thu, 9 Sep 2010, Lyle Giese wrote: David Forrest wrote: On Thu, 9 Sep 2010, Lyle Giese wrote: I am trying to install bind 9.7.1-P2 from source on a SLES 10 SP3 server. When I run named from the command line, it runs, but fails to open and write any of the zone

Re: installing on SLES 10sp3

2010-09-09 Thread Lyle Giese
. I am not using the -u option nor am I running in a CHROOT environment. ps shows root owning the named process. Also, there are specific issues when running the Security Enhanced Linux. This may be your situation, or not. We can't tell. I have never on purpose enabled SELinuxGRIN! Lyle Giese

Re: www.ncbi.nlm.nih.gov / pubmed

2010-08-19 Thread Lyle Giese
, not to exceed x numbers of days. That way we don't add a domain and mistype the expiration date or forget we created an exception for it. Lyle Giese LCR Computer Services, Inc. I did, and I disagree that it misses the point. I wanted a *short term* workaround for that zone, while the site fixed

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Lyle Giese
. I don't believe that BIND pays any attention to /etc/hosts.allow Lyle Giese LCR Computer Services, Inc. ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

  1   2   >