Re: RPZ and negative answers

2013-04-04 Thread Torsten Segner
Am Thu, 4 Apr 2013 23:51:23 GMT schrieb Vernon Schryver : > > From: Chris Buxton > > > A company wants to halt the spread of a piece of malware that > > uses DNS lookups to find its C&C. ... > > > The company has determined the first N domains of the sequence, > > but does not know how to calcu

Re: What can cause excessive amount of _dns-sd queries?

2012-08-23 Thread Torsten Segner
Am Thu, 23 Aug 2012 13:43:32 +0200 schrieb "Eivind Olsen" : > Hello. > > I haven't seen this before.. I'm currently seeing someone (1 ip address) > do about 2.1 million queries / hour where a majority of the queries seem > to be: > > b._dns-sd._udp.0.129.16.172.in-addr.arpa IN PTR + > db._dns-sd

Re: how can i start and stops bind service using named command

2012-03-07 Thread Torsten Segner
Am Thu, 8 Mar 2012 10:10:04 +0300 schrieb mustafa alhussona : > hi > i have bind9.9.0 installed manually now i want to start the service using > the command named i used named -fg to start it and it works, now how i can > stop it the man named page is encrypted and the options of this command are

Re: dnssec-keygen not responding

2011-11-30 Thread Torsten Segner
Am Wed, 30 Nov 2011 09:40:44 +0100 schrieb Adam Tkac : > On Wed, Nov 30, 2011 at 12:18:04AM -0500, Alan Clegg wrote: > > On 11/30/2011 12:15 AM, vishesh kumar wrote: > > > Hi All > > > > > > I am trying to generate keys for signing vishesh.com > > > domain using following com

Re: Port number in A record in zone file

2011-11-17 Thread Torsten Segner
Am Thu, 17 Nov 2011 14:46:45 +0100 schrieb Aleksander Kurczyk : > Hello, > Yesterday I asked here how can I run multiple named processes on different > ports in one OS. Now I have some troubles with that. How can I specify the > port number in zone file A record? > There is a simple answer: Y

Re: allow-transfer not covering ixfr requests?

2011-09-28 Thread Torsten Segner
Am Tue, 27 Sep 2011 22:03:44 +0200 schrieb "Tom Schmitt" : > > > > > The odd part is that both NS3 and NS4 weren't able to request ixfr > > transfers. > > Shouldn't allow-transfer cover these kind of transfer requests as well? > > > > > First: Do you have statements "provide ixfr;" and "requ

allow-transfer not covering ixfr requests?

2011-09-27 Thread Torsten Segner
I recently observered a rather strange phaenomenon. By accident I have configured a nameserver to allow queries from NS1 and NS2 and allow transfers from NS3 und NS4. So far so good... Naturally NS1 and NS2 could do all kinds of queries but no zone transfers. NS3 and NS4 weren't allowed to ask

Re: Problems with nic.it

2011-09-20 Thread Torsten Segner
Am Tue, 20 Sep 2011 09:20:12 +0200 schrieb Lucio Crusca : > Hello *, > > I'm new here though I've been using bind for about 10 years. I've just > transferred a domain under the .it TLD for the first time. > > Here in Italy we have nic.it that regulates the .it domain names > registrations > a

Re: CVE-2011-1910 vs bind 9.6-ESV-R4-P3

2011-08-03 Thread Torsten Segner
Am Wed, 3 Aug 2011 11:25:07 +0200 schrieb Issam Harrathi : > Hi all, > when i see this about the affected version by the CVE-2011-1910: 9.6: 9.6.3, > 9.6-ESV-R2, -R3, -R4, -R5b1 > does this mean that the 9.6-ESV-R4-P1 is affected? > > Thanks. > Issam Harrathi. No, because 9.6-ESV-R4-P1 is a pat

Re: DNS Caching Issue

2011-07-26 Thread Torsten Segner
Am Mon, 25 Jul 2011 08:22:00 -0600 schrieb "Sathyan Arjunan (sarjunan) [CONTRACTOR]" : > Recent days, I am facing frequent caching issues with my DNS servers > which are responsible for recursive lookup to external queries. As a > temporary solution, we used to refresh the named daemon to clear th

Re: MX choosing

2011-07-22 Thread Torsten Segner
Am Fri, 22 Jul 2011 16:50:35 +0800 schrieb Feng He : > Given the MX hosts for sympatico.ca domain: > > $ dig sympatico.ca mx +short > 5 mxmta.sympatico.ca. > > $ dig mxmta.sympatico.ca +short > 67.69.240.17 > 67.69.240.24 > 67.69.240.22 > 67.69.240.23 > 67.69.240.21 > 67.69.240.20 > 67.69.240.19

Re: Wild cards in zone file

2011-05-24 Thread Torsten Segner
Am Tue, 24 May 2011 09:55:19 +0100 schrieb John Kennedy : > I tried to google this but could not hit the right keywords (been a long > week)... > > I have 3 hosts on a domain (example.com) like so: > > int.project A 10.10.10.2 > stage.project A 10.10.10

Re: slave AXFR bind9

2011-04-21 Thread Torsten Segner
My first thoughts on this: Has the slave received a notify from the master server? Does the slave accept the notify? What else is in the logs? Could you please also provide your named configuration (options and the zone statement) of both master and slave? Ciao Torsten Am Thu, 21 Apr 2011

Re: rndc: 'reload' failed: not found

2011-03-08 Thread Torsten Segner
This usually happens when your nameserver isn't configured for the zone to be reloaded. Ciao Torsten Am Tue, 8 Mar 2011 14:47:02 +0800 schrieb "ShanyiWan" : > Cent OS+BIND 9.7.3+DLZ(BDB as backend) > > # rndc reload 2mysite.net > rndc: 'reload' failed: not found > > "rndc reload" not work

rrset-order and resolvers

2009-02-11 Thread Torsten Segner
servers? Ciao Torsten -- Torsten Segner | Systemadministrator Internet Services | Easynet GmbH T +49 (0)40 77175 650 | F +49 (0)40 77175 569 E torsten.seg...@de.easynet.net | GPG KeyID 0xC84C7841 Harburger Schlosstrasse 1 21079 Hamburg, Germany. www.easynet.com Geschäftsführer: Diethelm