Re: Re: Audit the consistency of zone files on DNS servers

2014-03-17 Thread Maren S. Leizaola
Thanks for your reply. Maybe I am a skeptic, but I am not skeptic of just bind, skeptic about myself and any script that is generating zones, all I know that things go wrong... including things caused by my own mistakes. 1. I now run a Bind and other DNS servers. I am not sure if inter oper

Re: Audit the consistency of zone files on DNS servers

2014-03-15 Thread Kevin Darcy
On 3/15/2014 6:09 AM, Maren S. Leizaola wrote: On 3/15/2014 1:53 AM, Kevin Darcy wrote: On 3/14/2014 8:28 AM, Maren S. Leizaola wrote: Hello, What do you guys recommend to audit every resource record in a zone file against all the records in all the DNS servers that host the zo

Re: Audit the consistency of zone files on DNS servers

2014-03-15 Thread /dev/rob0
On Sat, Mar 15, 2014 at 01:14:39PM +, Phil Mayers wrote: > On 15/03/2014 10:09, Maren S. Leizaola wrote: > >We are never sure how bug free bind is. As I am using other > >DNS servers I am not sure how reliably they interactive with > >Bind... So trust I nothing until it has been provent to work

Re: Audit the consistency of zone files on DNS servers

2014-03-15 Thread Phil Mayers
On 15/03/2014 10:09, Maren S. Leizaola wrote: Can someone provide an answer that does not refer to zone transfers? Your original email said: What I want to be able to detect are serial number errors, where a zone has been updated but the serial number has not changed Then you said: I am

Re: Re: Audit the consistency of zone files on DNS servers

2014-03-15 Thread Maren S. Leizaola
On 3/15/2014 1:53 AM, Kevin Darcy wrote: On 3/14/2014 8:28 AM, Maren S. Leizaola wrote: Hello, What do you guys recommend to audit every resource record in a zone file against all the records in all the DNS servers that host the zone file. I want something that I feed the mast

Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Mark Elkins
On Fri, 2014-03-14 at 14:54 -0400, Kevin Darcy wrote: > On 3/14/2014 2:39 PM, Maren S. Leizaola wrote: > > On 3/14/2014 9:20 PM, Stephane Bortzmeyer wrote: > >> On Fri, Mar 14, 2014 at 12:33:47PM +, > >> Phil Mayers wrote > >> a message of 25 lines which said: > >> > >>> dig @server zone a

Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Kevin Darcy
On 3/14/2014 2:39 PM, Maren S. Leizaola wrote: On 3/14/2014 9:20 PM, Stephane Bortzmeyer wrote: On Fri, Mar 14, 2014 at 12:33:47PM +, Phil Mayers wrote a message of 25 lines which said: dig @server zone axfr >file diff file file.real If you're really paranoid, it may not be sufficien

Re: Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Maren S. Leizaola
On 3/14/2014 9:20 PM, Stephane Bortzmeyer wrote: On Fri, Mar 14, 2014 at 12:33:47PM +, Phil Mayers wrote a message of 25 lines which said: dig @server zone axfr >file diff file file.real If you're really paranoid, it may not be sufficient since a server may reply differently to "norma

Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Kevin Darcy
On 3/14/2014 8:28 AM, Maren S. Leizaola wrote: Hello, What do you guys recommend to audit every resource record in a zone file against all the records in all the DNS servers that host the zone file. I want something that I feed the master zone file and then goes to each NS serv

Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Phil Mayers
Quite right I should have noted the need to canonicalise. -- Sent from my phone with, please excuse brevity and typos___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lis

Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Stephane Bortzmeyer
On Fri, Mar 14, 2014 at 12:33:47PM +, Phil Mayers wrote a message of 25 lines which said: > dig @server zone axfr >file > diff file file.real If you're really paranoid, it may not be sufficient since a server may reply differently to "normal" DNS queries and to zone file transfer requests

Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Stephane Bortzmeyer
On Fri, Mar 14, 2014 at 12:33:47PM +, Phil Mayers wrote a message of 25 lines which said: > dig @server zone axfr >file > diff file file.real diff is not clever enough, you'll find many spurious differences. Try feeding the two files (the local one and the AXFRed one) through named-compil

Re: Audit the consistency of zone files on DNS servers

2014-03-14 Thread Phil Mayers
On 14/03/14 12:28, Maren S. Leizaola wrote: Hello, What do you guys recommend to audit every resource record in a zone file against all the records in all the DNS servers that host the zone file. I want something that I feed the master zone file and then goes to each NS s

Audit the consistency of zone files on DNS servers

2014-03-14 Thread Maren S. Leizaola
Hello, What do you guys recommend to audit every resource record in a zone file against all the records in all the DNS servers that host the zone file. I want something that I feed the master zone file and then goes to each NS server and ensures that each of the records are