Re: nsupdate ACL based on a key AND ip-subnet

2008-11-17 Thread Niall O'Reilly
On Fri, 2008-11-14 at 17:35 -0800, Chris Buxton wrote: Use a firewall (with deep packet inspection) to restrict by subnet. Then use the TSIG key in the allow-update statement. Unfortunately, to my knowledge, that's the only way to do this. Wouldn't using a BIND view to restrict by

Re: Is it possible to use one KSK for multiple domains?

2008-11-20 Thread Niall O'Reilly
in the DNSKEY RRsets of multiple zones. I haven't read 4033/4034 thoroughly, so it's possible I may have misunderstood completely. Best regards, Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https

Re: 512 byte limit

2009-01-21 Thread Niall O'Reilly
On Wed, 2009-01-21 at 11:47 -0500, Todd Snyder wrote: I was under the (likely mistaken) impression that over 512 wasn't allowed, but there it is ... I could very well be completely messed up regarding the rules, so please forgive my ignorance. If you know my answer is in TFM, please batter

Re: denied NS/IN

2009-01-21 Thread Niall O'Reilly
On Wed, 2009-01-21 at 12:44 +1100, Mark Andrews wrote: You should talk to your ISP to chase the traffic back to its source and get BCP 38 implemented there. BCP 38 is ~10 years old now. There is no excuse for not filtering spoofed traffic. Absolutely.

Re: denied NS/IN

2009-01-22 Thread Niall O'Reilly
On Thu, 2009-01-22 at 10:25 +1100, Mark Andrews wrote: One way to test is to have a test box that sends spoofed traffic to a machine you control. Thanks, Mark. That tells me pretty well what I needed to know, but hoped not to hear: I have to build my own bot-net. 8-)

Re: rndc halt -p behavior

2009-01-22 Thread Niall O'Reilly
On Wed, 2009-01-21 at 19:14 -0600, Jeremy C. Reed wrote: Maybe we should just remove the immediately part. Any suggestions would be appreciated. If you're going to make a change, adding a little more information wouldn't hurt, would it? Perhaps: s/immediately/cleanly

Re: Open Ports in BIND

2009-02-01 Thread Niall O'Reilly
[ Copied to list to let other know that this question has been answered ] On Sun, 2009-02-01 at 18:08 +0330, Bind wrote: # netstat -an |grep 53 |wc 3911223 20656 is first number the total queries which asked from my server on port 53 or number of sessions

Re: Pruning the reverse zone tree

2009-02-04 Thread Niall O'Reilly
On Wed, 2009-02-04 at 16:57 +, Chris Thompson wrote: I would welcome feedback on http://people.pwf.cam.ac.uk/cet1/prune-reverse-zones which describes a scheme we are experimenting with for reverse lookup. (Executive summary: take RFC 2317 and carry the ideas to their [possibly]

Re: How to create the TSIG?

2009-02-06 Thread Niall O'Reilly
On Thu, 2009-02-05 at 16:58 -0800, Chris Buxton wrote: Use a different key for each slave. Definitely, if each of your slaves is under distinct administration. If some organization is managing more than one of your slaves for you, I'ld suggest using a distinct

adb.c:1526: INSIST(find-adbname == ((void *)0)) failed

2009-02-14 Thread Niall O'Reilly
joe(user)8: uname -a Linux marlay.no8.be 2.6.9-1.667 #1 Tue Nov 2 14:41:31 EST 2004 i586 i586 i386 GNU/Linux joe(user)9: named -v BIND 9.4.2-P1 joe(user)10: grep INSIST /var/log/messages.1 Feb 13 14:12:57 marlay named[2226]: adb.c:1526: INSIST(find-adbname == ((void *)0)) failed joe(user)11:

Re: adb.c:1526: INSIST(find-adbname == ((void *)0)) failed

2009-02-17 Thread Niall O'Reilly
On Mon, 2009-02-16 at 12:17 +1100, Mark Andrews wrote: It should be unrelated. I would however still upgrade. Thanks, Mark. If I don't see the same assertion failure with the current release, I guess that's closed. One advantage of upgrading is getting all

Re: adb.c:1526: INSIST(find-adbname == ((void *)0)) failed

2009-02-17 Thread Niall O'Reilly
On Tue, 2009-02-17 at 14:09 -0600, David Forrest wrote: To get rid of all those nice log entries, I have this in my named.conf: Thanks, David. For now, they're not so frequent as to be a nuisance. /Niall ___ bind-users

Re: Question re separating caching and authoritative servers

2009-02-20 Thread Niall O'Reilly
On Fri, 2009-02-20 at 13:07 -0500, John Wobus wrote: Any especially good or bad practices? Things that have worked well or poorly? Right now, I'm leaning toward having the caching server transfer key zones. Works for me. Niall O'Reilly University College Dublin

Re: XFR quota setting?

2009-03-11 Thread Niall O'Reilly
and succeeds after a couple of seconds. Best regards Niall O'Reilly University College Dublin IT Services ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: XFR quota setting?

2009-03-11 Thread Niall O'Reilly
On Wed, 2009-03-11 at 16:41 -0500, Peter Laws wrote: Seriously, though, what is the default quota and is it actually configurable? Sorry. No idea what or whether. RTFM time for us both! 8-) Although the '... quota reached' messages alarmed me at first, the following

Re: NOTIFY from masters when slave provides several views

2009-03-27 Thread Niall O'Reilly
On Thu, 2009-03-26 at 19:46 -0400, terry+bindus...@tmk.com wrote: Importantly, neither the masters nor ns1/2/3 have different zone data in different views - the answers are always the same. If you don't have different zone data per view, I don't understand what purpose the views

Re: Stats

2009-03-27 Thread Niall O'Reilly
On Fri, 2009-03-27 at 09:25 -0400, John D. Vo wrote: What do you guys use to turn this: --- Statistics Dump --- (1238151600) +++ Statistics Dump +++ (1238155200) success 3280261 referral 363 nxrrset 745513 nxdomain 392614 recursion 1173408 failure 1115632 --- Statistics Dump ---

Re: NOTIFY from masters when slave provides several views

2009-03-28 Thread Niall O'Reilly
On Fri, 2009-03-27 at 23:48 -0400, Terry Kennedy wrote: If you can describe how to handle the recursion issue without using views or multiple DNS servers, I'd be very interested. Perhaps allow-recursion { address_match_list }; would meet your needs. See section 6 of the

Re: DR bind

2009-04-23 Thread Niall O'Reilly
is NOT a master, you'll need to take some extra care. Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: nsupdate delete question

2009-04-30 Thread Niall O'Reilly
On Thu, 2009-04-30 at 10:18 -0400, James M wrote: trying to delete a nonexistant host does not return an error. That seems reasonable to me, since the state of the zone file after the transaction is indeed the state which would be expected, had the host been present and

Re: Regexp issue in NAPTR rewrite

2009-05-12 Thread Niall O'Reilly
sandoche BALAKRICHENAN wrote: I want to rewrite a query of the form sgtin.5.4.0.0.0.1.3.2.4.5.6.7.6.id.onsam.test to sgtin.5.4.0.0.0.1.3.2.4.5.6.7.6.id.onseu.test using NAPTR rewrite. The NAPTR RR in the zone config is as follows: sgtin.5.4.0.0.0.1.3.2.4.5.6.7.6.id.onsam.testIN

Re: Transfer delays

2009-05-28 Thread Niall O'Reilly
Todd Snyder wrote: Do you have notify no; in your config options? ... and you replied, No. What may be useful, and I haven't seen suggested in the other replies so far, is to check your logs (and eventually packet-captures) to confirm that the master is indeed

Re: Setting up tkey

2009-06-04 Thread Niall O'Reilly
relationship has a specific secret, but we, as well as any organization carrying multiple zone instances for us, are spared the administrative overhead of managing too many secrets. ATB Niall O'Reilly University College Dublin IT Services

Re: IPv6 reverse delegation

2009-07-02 Thread Niall O'Reilly
Akolinare wrote: Hello Mark, thank you very much for your quick answer. I'm sorry for express unclear. Creating of the reverse zone file is good documented and no problem. Both nameserver are already set up and work fine, except that the queries for the special subnets are not delegate from

Re: Correction to signatures on yesterday's BIND 9 releases

2009-07-31 Thread Niall O'Reilly
Evan Hunt wrote: reading carefully to the end of the line and notice that the 2006 Perhaps some people who did validate the files were similarly incautious. Or decided, taking account of the circumstances, not to treat expired as a synonym for not trustworthy. /Niall

Re: no more recursive clients: quota reached

2009-08-27 Thread Niall O'Reilly
, but only ever as a consequence of a back-hoe incident or similar catastrophe which isolates one of our campuses where there is a local resolving server. Best regards, Niall O'Reilly University College Dublin IT Services

Re: Feature request - disable internal recursion cache

2009-10-30 Thread Niall O'Reilly
see the point. If you need some code, other than BIND named, to handle recursive queries from your clients, why not just have that code listening on the addresses configured in the stub resolver on each of the client systems? Best regards, Niall

Re: Strange CNAME issue

2010-01-20 Thread Niall O'Reilly
, Niall O'Reilly University College Dublin IT Services ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: AW: Disabling recursion causes browser hangs on clients with auto proxy config

2010-01-25 Thread Niall O'Reilly
names for which your name server is authoritative; likewise for more lines with subnets. Best regards, Niall O'Reilly University College Dublin IT Services ___ bind-users mailing list bind-users@lists.isc.org https

Re: Loopback alias

2010-03-04 Thread Niall O'Reilly
sudo bin/tests/system/ifconfig.sh down I hope this helps. Best regards, Niall O'Reilly University College Dublin IT Services ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind

Re: why dig +trace does not working?

2010-06-14 Thread Niall O'Reilly
, which isn't authoritative for the zone of interest, so dig follows the referral chain until it arrives at ns2.dns-diy.com, which is also authoritative, and so provides dig with the result you asked for. I hope this helps. Best regards Niall

Re: why dig +trace does not working?

2010-06-14 Thread Niall O'Reilly
; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 ;; WARNING: recursion requested but not available [SNIP] Se last line. Ehm, no. With +trace, dig doesn't request recursion, but takes control of following the referral chain itself. Best regards Niall

Re: recursing stop at about 1000 clients

2010-07-15 Thread Niall O'Reilly
, or other sources of information. I hope this helps. Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Multiple masters and multiple TSIG keys

2010-09-29 Thread Niall O'Reilly
On 29 Sep 2010, at 09:34, Anand Buddhdev wrote: Now, I have been given 2 keys, t1 and t2, to use for transferring z1 and z2 respectively. [Wandering off topic, perhaps] That seems to me a back-to-front way to do things. If the organization running the master is

Re: Multiple masters and multiple TSIG keys

2010-09-29 Thread Niall O'Reilly
On 29 Sep 2010, at 15:53, Anand Buddhdev wrote: Anyway, I discussed this with my colleague here, and we came up with a solution that works. We have created 2 views of the master name servers: Nice one, and useful to have in the mailing-list archive! /Niall

Re: DNS Redundancy

2010-10-21 Thread Niall O'Reilly
when you take one of your authoritative servers down. Best regards, Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Dynamic DNS with secondary nameserver?

2010-12-01 Thread Niall O'Reilly
Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: nslookup Got recursion not available from... trying next server

2011-01-05 Thread Niall O'Reilly
. As it happens, 'dig' also makes a recursive query by default, although it's easy to tell it not to. Besides, 'dig' just shows the flags; it doesn't convert them into potentially disturbing messages. I hope this helps. Best regards, Niall O'Reilly

Re: bind slave not get DNS update

2011-01-05 Thread Niall O'Reilly
on the NOTIFY. That should make it clear what's not happening without manual intervention. Best regards, Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: check the master/slave status

2011-01-07 Thread Niall O'Reilly
are excellent. Either of these will give you some ideas about what to include in the script you want to write. Have fun! Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo

Re: failed multi-view zone transfer

2011-01-26 Thread Niall O'Reilly
On 22 Jan 2011, at 18:29, jeffreyp wrote: it's the transfers that are not happening. and, specifically, just the transfers of the internal view to the slave on the different subnet. You've mentioned that the slave receives and logs the NOTIFY. Do you see it (trying to) start

Re: About name servers registration

2011-03-10 Thread Niall O'Reilly
On 10 Mar 2011, at 08:44, Torinthiel wrote: Bujt the procedure still is same. A solution (not necessarilty better) involving less typing would be dig +trace dnsbed.com ns /Niall ___ bind-users mailing list

Re: AW: ipv6 PTR in zone file

2011-04-12 Thread Niall O'Reilly
pint $foo-reverse_ip() 2.4.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. pint ^D dhcp-c101a88b(niall)6: Best regards, Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org

Re: How to Setup a Name Servers visible on Internet?

2011-06-21 Thread Niall O'Reilly
name servers. If you think you've already done this, you should look for a spelling error or an omitted dot. Kind regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: Problems with nic.it

2011-09-20 Thread Niall O'Reilly
this helps. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Delegation check failed

2011-09-21 Thread Niall O'Reilly
Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Delegation check failed

2011-09-21 Thread Niall O'Reilly
for clarifying, Kevin. I hadn't tried the Undelegated domain test until just now. I see. Best rregards Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: I can dig a domain but named won't resolve it.

2011-09-22 Thread Niall O'Reilly
packet capture to find out what's not happening. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: I can dig a domain but named won't resolve it.

2011-09-22 Thread Niall O'Reilly
. You might find https://www.dns-oarc.net/oarc/services/porttest an interesting read. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

BIND 9.8.1-P1: 'make test' fails

2011-11-22 Thread Niall O'Reilly
Since quite a few years, I habitually run 'make test' after building BIND from sources. I'me seiing a failure with 9.8.1-P1, and wonder whether anyone else is also. Relevant log fragment is shown below. /Niall S:xfer:Tue Nov 22 11:12:07 GMT 2011

Re: BIND 9.8.1-P1: 'make test' fails

2011-11-28 Thread Niall O'Reilly
On 22/11/11 18:10, /dev/rob0 wrote: Is this a manifestation of the same issue as brought up last week? https://lists.isc.org/pipermail/bind-users/2011-November/085593.html I don't think so. I can compile without problem. I see a failure during 'make test' processing, and

Re: Permissions change after running dnssec-settime bind 9.9.0rc2

2012-02-01 Thread Niall O'Reilly
On 1 Feb 2012, at 09:52, Phil Mayers wrote: As is probably obvious, I consider it an irritating bug ;o) +1 Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: State diagram for DNSsec key lifecycle

2012-02-10 Thread Niall O'Reilly
regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Master/slave configuration

2012-03-08 Thread Niall O'Reilly
On 8 Mar 2012, at 02:58, Lyle Giese wrote (on bind-users): On linux boxes, adding options rotate to the /etc/resolv.conf helps. [cross-posted, reply-to header set] Is there a DHCP option which expresses that, and which typical fielded DHCP clients will respect?

Re: Restricting access keeping identical data across views

2012-03-28 Thread Niall O'Reilly
to contributing some effort to such a project. ATB Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: Restricting access keeping identical data across views

2012-03-28 Thread Niall O'Reilly
. The devil is in the details, which I'll spare you! 8-) Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org

Re: erros in logs

2012-05-10 Thread Niall O'Reilly
expect to see these all the time when you run a resolver. There are broken and misconfigured servers out there! I hope this helps. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: Transfer the same zone from a split-view master

2012-06-06 Thread Niall O'Reilly
expected to happen, and what actually happened. People won't help unless they believe you're making a serious effort; so far, you haven't sent anything which might convince them. Best regards, Niall O'Reilly University College Dublin

Several (2) different views

2012-06-15 Thread Niall O'Reilly
captive view internal { match-clients { internal-clients; }; // view details go here ... }; // standard view: 'general' view general { match-clients { any; }; // view details go here ... }; I hope this helps. Niall O'Reilly

Re: Several (2) different views [SOLVED]

2012-07-09 Thread Niall O'Reilly
On 3 Jul 2012, at 21:21, Rodrigo Renie Braga wrote: Just giving a feedback, this method worked great, but in my case, didn't have no negate the keys in the ACL (like the example below), I created one key for each ACL in my configuration and used that ACL for the match-clients directive in

Re: Basic scope question

2012-07-10 Thread Niall O'Reilly
On 10/07/12 18:07, Bennett, Gary L. wrote: No, have that part. Was just wondering which domain-name-servers parm, global or in DHCP address pool, has precedence. Thanks. The more specific specific over-rides the global one. Niall O'Reilly

Re: recursive-clients recommended values

2012-07-12 Thread Niall O'Reilly
. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: SRV query with no domain?

2012-08-16 Thread Niall O'Reilly
On 16 Aug 2012, at 15:42, Christopher Cain wrote: Of course a dig query will fail without the domain appended. Dig takes you query at face value and will not append domains from your search suffix list like nslookup and ping will. You ALWAYS have to fully qualify your requests when using

Re: ho to filter hundeds of domains ?

2012-08-30 Thread Niall O'Reilly
resources to chasing a moving target. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: question about how a particular dig works ...

2012-09-18 Thread Niall O'Reilly
On 18 Sep 2012, at 14:45, M. Meadows wrote: dig www.careerone.com.au +short @8.8.8.8 www.careerone.com.au.edgesuite.net. a903.g.akamai.net. 208.44.23.99 208.44.23.121 Why does the above dig work when If you try dig +trace www.careerone.com.au you'll find that the

RH release selection (was: Moving from type forward to type static-stub)

2012-09-21 Thread Niall O'Reilly
On 21 Sep 2012, at 08:55, Adam Tkac wrote: Because rc2 was released too late to get it into RHEL 6.3... Btw which is the bug that bothers you? Why don't you report it to RH bugzilla? I don't understand why RH would choose to include a release candidate rather than a stable

Re: dhcpd

2012-10-19 Thread Niall O'Reilly
instead of BOOTP. Jim Glassford's suggestion seems good enough to me. On 18 Oct 2012, at 14:28, Jim Glassford wrote: We just continue to deny bootp for subnets that have no need for it and ignore them. Best regards, Niall O'Reilly University College Dublin

Re: Update view without using 2 ip for each DNS Server

2012-12-04 Thread Niall O'Reilly
The example in the last one is extracted from a live configuration which I'm responsible for. Best regards, Niall O'Reilly University College Dublin IT Services ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: what do you use for logging?

2013-01-18 Thread Niall O'Reilly
On 17 Jan 2013, at 20:58, Mike Hoskins (michoski) wrote: Syslog as the default is perfectly fine with us. Please keep that as the default, following the principle of least astonishment. I do also use the rotated file method a few places, so hoping that doesn't disappear.

Re: what do you use for logging?

2013-01-18 Thread Niall O'Reilly
On 18 Jan 2013, at 06:27, Jan-Piet Mens wrote: Could CLI utility be man(1) and info(1)? :-) It could, yes, but `b10-msg NNN` isn't going to break BIND 10's development budget (I hope), +1 and I feel it to be more practical than scrolling through a man page with 900+

Re: what do you use for logging?

2013-01-18 Thread Niall O'Reilly
? Definitely. Do any packagers provide a configuration with different-than-default logging setup? (What and why?) I'm sorry; I don't know. Apart from one exceptional NetBSD box, I always build from source and avoid whatever the packager offers. Best regards Niall

Re: BIND9 statistics-server: JSON?

2013-02-15 Thread Niall O'Reilly
On 15 Feb 2013, at 05:57, Jan-Piet Mens wrote: would there be a chance of ISC adding this to stock BIND9? Even better: would ISC take on the work of doing it? ;-) FWIW: +1 /Niall ___ Please visit

Re: Blocking private addresses with a optionq

2013-03-14 Thread Niall O'Reilly
On 14 Mar 2013, at 15:57, Chris Buxton wrote: No, I'm pretty sure the OP wants to strip records from responses if the records are A records referring to private address space (RFC 1918). I've no idea how you would do this. Other than separate views, with a trimmed zone in the

Re: Blocking private addresses with a optionq

2013-03-14 Thread Niall O'Reilly
On 14 Mar 2013, at 16:22, Chris Buxton wrote: Well, yes, if the server in question is authoritative for all the data in question. But if it's just a resolver, that may be more difficult. Fair comment. I was (perhaps naïvely) being led by my aversion to open resolvers

Re: Suspecious DNS traffic

2013-03-25 Thread Niall O'Reilly
, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Some Server not Resolving certain address

2013-04-08 Thread Niall O'Reilly
@127.0.0.1 ... you can be sure that the server on which your shell session is running is the one to which dig sends the query. If this is not what you need, use the address of the server's network interface. ATB Niall O'Reilly

Re: Reverse address entries

2013-06-28 Thread Niall O'Reilly
On Fri, 28 Jun 2013 13:57:44 -0400 Novosielski, Ryan novos...@umdnj.edu wrote: The short answer is some software once cared. Does it still now, I'm not sure. But we do it. Some still does Niall O'Reilly ___ Please visit https

Re: Slave not creating/updating zones

2013-07-15 Thread Niall O'Reilly
On 15 Jul 2013, at 12:49, Grace Ingabire wrote: The issue is now resolved, my master was not configured properly! There's something else: LTD.RW seems not to be delegated. The problem seems to be masked from you because this zone and its parent are both hosted on

Re: BIND 9.8.1-P1: 'make test' fails

2013-08-20 Thread Niall O'Reilly
On 22 Nov 2011, at 11:24, Niall O'Reilly wrote: Since quite a few years, I habitually run 'make test' after building BIND from sources. I'me seiing a failure with 9.8.1-P1, and wonder whether anyone else is also. [By way of putting this to bed, at last ...] Updating

Re: BIND 9.8.1-P1: 'make test' fails

2013-08-20 Thread Niall O'Reilly
On 20 Aug 2013, at 15:08, Chris Buxton wrote: There is a mailing list for Net::DNS. List-Subscribe: https://www.nlnetlabs.nl/mailman/listinfo/net-dns-users, mailto:net-dns-users-requ...@nlnetlabs.nl?subject=subscribe That said, there was a discussion last December about what has changed

Re: ISO or virtual appliance

2013-08-22 Thread Niall O'Reilly
www.example.com as a tiny dynamic zone and update it directly. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: packet size

2013-09-11 Thread Niall O'Reilly
On 11 Sep 2013, at 17:24, Maria Iano wrote: What does it mean when the edns0 response to a dig says the overall packet size will be one value Not will be one value but can be no more than that value. but the message size reported is different. That's the actual size of the

Re: use bind 9.8 as caching server and authoritative nameserver

2013-10-30 Thread Niall O'Reilly
-council-shares-its-report-on-dns-based-internet-filtering.html Best regards, Niall O'Reilly Member of AFNIC's Conseil Scientifique PS. I wan't a significant contributor to this report. Credit for that belongs to the colleagues who did the work. /Niall

Re: Recursive DNS server cannot resolve the reverse zone records from my IPv6 private network

2013-11-07 Thread Niall O'Reilly
) in the zone file you're using. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo

Re: missing ‘additional section’

2013-12-19 Thread Niall O'Reilly
On 18 Dec 2013, at 15:19, houguanghua houguang...@hotmail.com wrote: Is there any way to enable the Additional Section? Thanks. The server sends data in the additional section if either (a) these data are required, or (b) the server supports and is configured to send

Re: bad owner name - Unable to add forward map from Nintendo Wii U ... REFUSED

2013-12-27 Thread Niall O'Reilly
the configuration of this server, I expect you're in a position to determine what owner name is passed to the DNS server, and that this approach might be what you need. This thread probably belongs better on the dhcp-users list ... Niall O'Reilly ___ Please

Re: intermittent resolving problem for some domains

2014-02-19 Thread Niall O'Reilly
is giving these messages can reach any of the root servers or even any of the external Internet. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list

Re: How to setup a backup NameServer?

2014-04-29 Thread Niall O'Reilly
At Tue, 29 Apr 2014 10:24:58 +, houguanghua wrote: Yes, I had asked the same question months ago. I'm designing how to protect DNS for an ISP. The zones are not owned by the ISP. The ISP wants to proect the DNS query during attacking. So it's not standard DNS solution. During the

Re: Does bind read /etc/hosts?

2014-07-15 Thread Niall O'Reilly
, please see http://serverfault.com/questions/498500/why-does-the-host-command-not-resolve-entries-in-etc-hosts Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: Digging to the final IP

2014-10-22 Thread Niall O'Reilly
At Tue, 21 Oct 2014 22:31:28 -0500, Frank Bulk wrote: Dave, Thanks for the input, but what I was looking for was a dig command that returns the IP(s) or a fail. It looks like the host command is the right solution in this case, not dig. Doesn't egrep fail on no match? Niall

Re: Digging to the final IP

2014-10-23 Thread Niall O'Reilly
At Thu, 23 Oct 2014 15:17:49 +0100, Sam Wilson wrote: In article mailman.1128.1414072988.26362.bind-us...@lists.isc.org, Bob Harold rharo...@umich.edu wrote: Anytime you see 'grep' and 'cut' used together, they can usually be shortened to just 'awk', which requires starting one less

Re: Digging to the final IP

2014-10-23 Thread Niall O'Reilly
At Thu, 23 Oct 2014 15:17:49 +0100, Sam Wilson wrote: In article mailman.1128.1414072988.26362.bind-us...@lists.isc.org, Bob Harold rharo...@umich.edu wrote: Anytime you see 'grep' and 'cut' used together, they can usually be shortened to just 'awk', which requires starting one less

Re: recursive-clients : recommended value for a high traffic recursive nameserver

2014-11-24 Thread Niall O'Reilly
, network problems, or some combination of these. Your logs will help identify which. I hope this helps. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing

Re: recursive-clients : recommended value for a high traffic recursive nameserver

2014-11-24 Thread Niall O'Reilly
, network problems, or some combination of these. Your logs will help identify which. I hope this helps. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing

Re: BIND response time is relatively high

2015-01-26 Thread Niall O'Reilly
At Mon, 26 Jan 2015 21:50:37 +, Darcy Kevin (FCA) wrote: The parameter that is glaringly missing from your list is “recursive-clients”. Do you have that set at default value (1000) or have you bumped it up higher? Since you say that this happens at “peak hours”, recursive-clients is

Re: BIND9 Return different IP address based on subnet

2015-01-05 Thread Niall O'Reilly
At Sat, 3 Jan 2015 19:24:47 +0100, Christian Kette wrote: I have found a workaround. I defined a different zone for every network A simpler solution might be to use a sortlist. From the ARM: 6.2.16.13 The sortlist Statement The response to a DNS query may consist of multiple resource

Re: lists subdomain not fully working [SOLVED]

2015-05-27 Thread Niall O'Reilly
On Wed, 27 May 2015 07:50:12 +0100, Lucio Crusca wrote: I've now fixed the MNAME and I have to wait propagation before testing again, but I'm really confident it will solve the problem, Fammi sapere, per piacere ... Niall ___ Please visit

Re: Issue in calling same zone in more than one VIEW

2015-05-29 Thread Niall O'Reilly
what I should do for getting rid of this issue. You need to use as many copies of each zone file as you have views needing to write to it. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: Issue in calling same zone in more than one VIEW

2015-05-29 Thread Niall O'Reilly
option referencing the first view. I hope this helps. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: Issue in calling same zone in more than one VIEW

2015-05-29 Thread Niall O'Reilly
On Fri, 29 May 2015 11:25:48 +0100, Cathy Almond wrote: From 9.10.0 there is a new zone type 'in-view'. From the release notes: Neat! Thanks and best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo

  1   2   >