Re: Bind9 Random Whois and Dig Fails

2011-06-07 Thread Stephane Bortzmeyer
On Fri, Jun 03, 2011 at 03:09:13PM -0700, Sri Harsha Yalamanchili har...@thought-matrix.com wrote a message of 145 lines which said: o query-source address X.X.X.X port 53; That's typically a very bad idea because it makes the source port predictable and therefore makes you much

Re: Bind9 Random Whois and Dig Fails

2011-06-07 Thread Sri Harsha Yalamanchili
The query-source address is nat'ed address inside the firewall. We opted for that to make our firewall less porous but may be we should re-visit that strategy. The forwarder actually works. That was the primary/only DNS server we were using until we decided to install our own internal dns and

Re: Bind9 Random Whois and Dig Fails

2011-06-07 Thread Chuck Swiger
On Jun 7, 2011, at 11:07 AM, Sri Harsha Yalamanchili wrote: Not much luck using tcpdump either. We know, from both the query_log and tcpdump logging, that the queries are going out. But we never get a reply back. That's the confusing part. The Google DNS server replies back but not our own

Bind9 Random Whois and Dig Fails

2011-06-03 Thread Sri Harsha Yalamanchili
Hey Everyone, We've setup and internal DNS on a Debian 6.0 Squeeze server with Bind 9 running on it. A few things specific to our configuration are: * This is not a caching only server. We've have our own internal domain. We also have a dns slave running on another server. The