I think it would be better to leave the edns-disabled category enabled.

Nowadays these messages are much rarer in normal circumstances, so
they're less of a problem (also, Debian's default logcheck rules make
logcheck ignore them).

Last week my employer's ISP did something which broke many outgoing DNS
requests using EDNS, and the sudden appearance of large numbers of
"disabling EDNS" and "reducing the advertised EDNS UDP packet size"
messages in Bind's logs made it much easier to identify the problem (and
work around it with 'edns no' until it was fixed).

Reply via email to