Re: Bind9 local DNS not forwarding query to public DNS

2024-03-12 Thread Dan Ritter
Muhammad Yousuf Khan wrote: > Need your experience advice, We have a BIND9 DNS server that operates both > privately and publicly for the domain example xyz.com. I use the private > DNS for certain secure nodes on our local network. I want all VPN users to > be able to resolve these secure nodes u

Re: Bind9 local DNS not forwarding query to public DNS

2024-03-12 Thread Eduardo M KALINOWSKI
On 12/03/2024 12:48, Muhammad Yousuf Khan wrote:   Dear All, Need your experience advice, We have a BIND9 DNS server that operates both privately and publicly for the domain example xyz.com . I use the private DNS for certain secure nodes on our local network. I want all VPN

Re: bind9 and dns forward

2023-06-01 Thread Michel Verdier
Le 1 juin 2023 Bonno Bloksma a écrit : >> If you get an answer it's a dnssec problem with the error message in your >> logs. If there is no answer it's another problem. > Well, it seems I get an answer with the +cd option, and none without. Yes. If I do : # dig tio.nl A +dnssec +multiline ; <<

RE: bind9 and dns forward

2023-06-01 Thread Bonno Bloksma
Hi, @Tim, If I use the dnssec-validation no; option then indeed it all works. Just tested it again to make sure. And as a final solution to this problem I might accept it, but I would rather not. @Michel, > I reread all our mails and I miss to ask you this one (as answers via > external dns

Re: bind9 and dns forward

2023-06-01 Thread Michel Verdier
Le 1 juin 2023 Bonno Bloksma a écrit : > I can do that, but ... that is only for inbound traffic TO my dns server on > this network. > That part is working without any problem. Changing that will not change > anything for the clients on this network. You are right. I simply used to fix explicit

RE: bind9 and dns forward

2023-06-01 Thread Tim Woodall
On Thu, 1 Jun 2023, Bonno Bloksma wrote: My bind instance can reach the company dns server buy claims the response is false/insecure Does that maybe mean that my bind gets a "normal" response from the company dns whereas the external dns at toplevel .nl. (being the parent zone) tells that an

RE: bind9 and dns forward

2023-06-01 Thread Bonno Bloksma
Hi, >> linbobo:~# ss -nap | grep named >> tcp LISTEN 0 10 [2a02:a45f:96c2:1:1e69:7aff:fe0c:65e3]:53 [::]:* >> users:(("named",pid=554,fd=78)) >> tcp LISTEN 0 10 [fe80::1e69:7aff:fe0c:65e3]%eno1:53 [::]:* >> users:(("named",pid=554,fd=71)) >> tcp LISTEN 0 10 [fe80::33bc:2b:d928:991d]%tun0:53 [::]:*

Re: bind9 and dns forward

2023-06-01 Thread Michel Verdier
Le 1 juin 2023 Bonno Bloksma a écrit : > linbobo:~# ss -nap | grep named > tcp LISTEN 0 10 [2a02:a45f:96c2:1:1e69:7aff:fe0c:65e3]:53 [::]:* > users:(("named",pid=554,fd=78)) > tcp LISTEN 0 10 [fe80::1e69:7aff:fe0c:65e3]%eno1:53 [::]:* > users:(("named",pid=554,fd=71)) > tcp LISTEN 0 10 [fe80::33bc

RE: bind9 and dns forward

2023-06-01 Thread Bonno Bloksma
Hi, > resolv.conf must have only one search entry. And you don't want to resolv > with google directly. So you should have : Ok, I have the google dns commented. Alhough Now I remember why I had the google dns in there. ;-) For my machine to create the VPN it needs to know the ip number of

Re: bind9 and dns forward

2023-05-23 Thread Michel Verdier
Le 19 mai 2023 Bonno Bloksma a écrit : > Been a few busy week, that is why I only respond now, sory. Same for me :/ > beheerdertio@linbobo:~$ cat /etc/resolv.conf > domain bobo.xs4all.nl > search bobo.xs4all.nl > search tio.nl > search staf.tio.nl > search student.tio.nl > nameserver 127.0.0.1 >

RE: bind9 and dns forward

2023-05-19 Thread Bonno Bloksma
Hi, Been a few busy week, that is why I only respond now, sory. Also as there is a lot of sensitive info in this mail, like a complete lost to domain controllers to be hacked, ;-) I am sending it direct. I will send a redacted version to the list >> What does +cd do? I was unable to find it

Re: bind9 and dns forward

2023-05-08 Thread Michel Verdier
Le 8 mai 2023 Bonno Bloksma a écrit : > I also do not understand this difference when querying the internal dns > server directly. > Why does the +trace +cd not show an answer but when I leave them out I get a > correct answer. Is that because +trace forces it to start at the root which is > irre

RE: bind9 and dns forward

2023-05-08 Thread Bonno Bloksma
Hi, >> linbobo:/etc/bind# cat named.conf.local > > You have only zone blocks in this file, right ? Yes, > And you don't use views ? I have no idea what they would do, but no. The word view is not in that file. > Why does it first go to the public dns and then run into the dnssec problem? > Th

Re: bind9 and dns forward

2023-05-05 Thread Michel Verdier
Le 5 mai 2023 Bonno Bloksma a écrit : > linbobo:/etc/bind# cat named.conf.local You have only zone blocks in this file, right ? And you don't use views ? > Why does it first go to the public dns and then run into the dnssec problem? > There is a direct definition for the tio.nl zone in my confi

RE: bind9 and dns forward

2023-05-05 Thread Bonno Bloksma
Hi, > In fact you don't resolv at all. Can you provide: > dig einsccmdp-01.tio.nl +trace +cd - linbobo:~# dig einsccmdp-01.tio.nl +trace +cd ; <<>> DiG 9.16.37-Debian <<>> einsccmdp-01.tio.nl +trace +cd ;; global options: +cmd . 430791 IN

Re: bind9 and dns forward

2023-05-02 Thread Michel Verdier
Le 2 mai 2023 Bonno Bloksma a écrit : > linbobo:/etc/bind# cat named.conf.local > --- > [] > zone "tio.nl" IN { > type forward; > forward only; > forwarders {172.16.128.40; 172.16.208.10;}; > }; > > zone "staf.tio.nl" IN { > type forward;

RE: bind9 and dns forward

2023-05-02 Thread Bonno Bloksma
Hi, Lots of info and log quotes. I hope you can find the "normal" text. >> We use a different dns server(s) and zonefile for the external dns >> environment from what we use internally. Company dns is Windows server 2016 >> incase that is relevant. > > It's better to use dig (package bind9-dns

Re: bind9 and dns forward

2023-04-29 Thread Michel Verdier
Le 28 avril 2023 Bonno Bloksma a écrit : > We use a different dns server(s) and zonefile for the external dns > environment from what we use internally. Company dns is Windows server 2016 > incase that is relevant. It's better to use dig (package bind9-dnsutils) to first eliminate problems on o

Re: bind9 slave sending notifies

2022-03-23 Thread Tim Woodall
On Thu, 24 Mar 2022, Jeremy Ardley wrote: I'm using BIND 9.16.22-Debian (Extended Support Version) The problem is when I restart I see "sending notifies" in the log. I have checked the configuration named.conf.local and named.conf.options and there is no 'allow-transfer' in the configuration

Re: bind9 startup problems: /var/cache /bind

2019-05-25 Thread Ross Boylan
I tested my suspicion that bind9-resolvconf was somehow implicated in the bind9 start problems by returning bind9-resolvconf to its original, disabled, state and restarting the system. Unfortunately, it didn't help: May 25 19:05:34 barley named[804]: /etc/bind/named.conf.options:2: change director

Re: bind9 startup problems: /var/cache /bind

2019-05-22 Thread Ross Boylan
On Wed, May 22, 2019 at 2:47 PM Richard Hector wrote: > > RequiresMountsFor=/absolute/path/of/mount > > .. to go in the unit file - or IIRC running: > > sudo systemctl edit bind9.service > > ... and putting in: > > ---8< > [Unit] > RequiresMountsFor=/var > ---8< > > ... fol

Re: bind9 startup problems: /var/cache /bind

2019-05-22 Thread Richard Hector
On 23/05/19 9:08 AM, Ross Boylan wrote: > /var is a separate file system, and like / it's encrypted, so it might > take a bit of time to activate it. Whether it's available when > needed, I don't know, though the error suggests it might not be. > Could systemd be launching services while some of t

Re: bind9 startup problems: /var/cache /bind

2019-05-22 Thread Ross Boylan
/var is a separate file system, and like / it's encrypted, so it might take a bit of time to activate it. Whether it's available when needed, I don't know, though the error suggests it might not be. Could systemd be launching services while some of the mounts (and the required decryption) are stil

Re: bind9 startup problems: /var/cache /bind

2019-05-22 Thread Richard Hector
On 23/05/19 8:00 AM, Ross Boylan wrote: > At system start, bind9 fails to start on a recently created buster > system. Some of the local bind is based on configuration from an > earlier bind. The logs show > /etc/bind/named.conf.options:2: change directory to '/var/cache/bind' > failed: file not

Re: bind9 needs sometimes a restart after resume from suspend

2014-12-02 Thread Bob Proulx
Karl E. Jorgensen wrote: > I wonder... What exactly does "bind not responding" mean? any command > that reproduces that would be handy. > > As this is happening in relation to suspend/resume, this would imply > that network interfaces go down and up too. So perhaps bind is failing > to detect the r

Re: bind9 needs sometimes a restart after resume from suspend

2014-12-02 Thread Karl E. Jorgensen
Hi On Sun, Nov 30, 2014 at 03:26:29PM +0100, Rainer Dorsch wrote: > On Sunday 30 November 2014 11:59:16 Karl E. Jorgensen wrote: > > Hi > > > > On Sun, Nov 30, 2014 at 12:26:36PM +0100, Rainer Dorsch wrote: > > > Hi Pascal, > > > > > > On Sunday 30 November 2014 11:15:41 Pascal Hambourg wrote: >

Re: bind9 needs sometimes a restart after resume from suspend

2014-11-30 Thread Rainer Dorsch
On Sunday 30 November 2014 11:59:16 Karl E. Jorgensen wrote: > Hi > > On Sun, Nov 30, 2014 at 12:26:36PM +0100, Rainer Dorsch wrote: > > Hi Pascal, > > > > On Sunday 30 November 2014 11:15:41 Pascal Hambourg wrote: > > > Hello, > > > > > > Rainer Dorsch a écrit : > > > > I run bind9 locally and

Re: bind9 needs sometimes a restart after resume from suspend

2014-11-30 Thread Martin Read
On 30/11/14 12:02, Andrew McGlashan wrote: On 30/11/2014 8:42 PM, Rainer Dorsch wrote: blackbox:/etc/bind# cat /etc/systemd/system/bind9-resume.service So ... buggy systemd bites yet again; This is *BIND* we're talking about; even if I was opposed to systemd, I probably wouldn't go jumping

Re: bind9 needs sometimes a restart after resume from suspend

2014-11-30 Thread Andrew McGlashan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 30/11/2014 8:42 PM, Rainer Dorsch wrote: > blackbox:/etc/bind# cat /etc/systemd/system/bind9-resume.service So ... buggy systemd bites yet again; and *some* [too many] people still don't understand why we don't want this on our Debian (or other)

Re: bind9 needs sometimes a restart after resume from suspend

2014-11-30 Thread Karl E. Jorgensen
Hi On Sun, Nov 30, 2014 at 12:26:36PM +0100, Rainer Dorsch wrote: > Hi Pascal, > > On Sunday 30 November 2014 11:15:41 Pascal Hambourg wrote: > > Hello, > > > > Rainer Dorsch a écrit : > > > I run bind9 locally and noticed that bind9 sometimes needs a restart after > > > suspend. > > > > Why ?

Re: bind9 needs sometimes a restart after resume from suspend

2014-11-30 Thread Rainer Dorsch
Hi Pascal, On Sunday 30 November 2014 11:15:41 Pascal Hambourg wrote: > Hello, > > Rainer Dorsch a écrit : > > I run bind9 locally and noticed that bind9 sometimes needs a restart after > > suspend. > > Why ? Not running, not resolving, errors... ? bind9 does not respond. See e.g. the dig comm

Re: bind9 needs sometimes a restart after resume from suspend

2014-11-30 Thread Pascal Hambourg
Hello, Rainer Dorsch a écrit : > > I run bind9 locally and noticed that bind9 sometimes needs a restart after > suspend. Why ? Not running, not resolving, errors... ? -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas..

Re: BIND9 Dynamic Update Zones

2014-11-19 Thread Pascal Hambourg
Roman Gelfand a écrit : > When I try run "nsupdate -d -L 9 nsu.tmp", where nsu.tmp is > > update add cmm3.workdom.com 3600 A 192.168.10.8 > show > send > > Dynamic zone file > > include "/etc/bind/zones.rfc1918"; > > zone "workdom.com" IN { > type master; > f

Re: bind9

2013-11-01 Thread Karl E. Jorgensen
Hi On Fri, Nov 01, 2013 at 01:10:33AM -0400, Roman Gelfand wrote: > My workstations' ips are assigned by dhcp server on firewall. The > bind9 is running on debian 7 box. Is there a way to automatically > update forward and reverse zones? In this configuration: probably not. Having the name ser

Re: bind9

2013-11-01 Thread Joe
On Fri, 1 Nov 2013 10:58:50 +0530 Arun Khan wrote: > On Fri, Nov 1, 2013 at 10:40 AM, Roman Gelfand > wrote: > > My workstations' ips are assigned by dhcp server on firewall. The > > bind9 is running on debian 7 box. Is there a way to automatically > > update forward and reverse zones? > > >

Re: bind9

2013-10-31 Thread Arun Khan
On Fri, Nov 1, 2013 at 10:40 AM, Roman Gelfand wrote: > My workstations' ips are assigned by dhcp server on firewall. The > bind9 is running on debian 7 box. Is there a way to automatically > update forward and reverse zones? > For known MAC addresses I usually assign 'fixed' ip addresses + th

Re: bind9

2013-10-04 Thread pch0317
I found in /var/log/daemon.log that not all zone are in view brackets. I solve the problem. Thanks On 10/03/2013 08:41 PM, Karl E. Jorgensen wrote: Hi On Thu, Oct 03, 2013 at 07:28:46PM +0200, Pawe?? Ch. wrote: Hi list I install bind9 server on debian (https://wiki.debian.org/Bind9). When I

Re: bind9

2013-10-03 Thread Karl E. Jorgensen
Hi On Thu, Oct 03, 2013 at 07:28:46PM +0200, Pawe?? Ch. wrote: > Hi list > > I install bind9 server on debian (https://wiki.debian.org/Bind9). When I add > named.conf.log entries bind9 can't start. Before adding log entries bind work > correctly. Without more information, diagnostics is guesswor

Re: bind9, openswan crashes wheezy VPS

2013-08-21 Thread Gregory Nowak
On Tue, Aug 13, 2013 at 01:37:32PM -0600, Bob Proulx wrote: > I will be curious to hear what you find out about your problem. > System crashes are always especially difficult for me to debug. > I'm closing this issue with my VPS provider, so wanted to follow up here as well. My VPS provider chang

Re: bind9, openswan crashes wheezy VPS

2013-08-13 Thread Bob Proulx
Gregory Nowak wrote: > Bob Proulx wrote: > without problems. So, it could very well be something with the > virtio_net module. Will be interesting to see what solves this. Good luck! > > BTW... What do you have in /etc/nsswitch.conf? Hope it just says > > "files dns" there. > > > > $ grep ho

Re: bind9, openswan crashes wheezy VPS

2013-08-13 Thread Gregory Nowak
On Mon, Aug 12, 2013 at 08:33:14PM -0600, Bob Proulx wrote: > I don't know but for example DNS will start off with a UDP query. But > if the response is too large for a single UDP packet then it will > change to a TCP connection for the larger data exchange. So let's say > that UDP always works o

Re: bind9, openswan crashes wheezy VPS

2013-08-12 Thread Bob Proulx
Gregory Nowak wrote: > On the other hand, if it's something in the network stack, why am I > for example able to query my VPS provider's servers for the same > domains without crashes? If it's in the network stack, then I think > it's reasonable to conclude I'd be seeing crashes regardless of what

Re: bind9, openswan crashes wheezy VPS

2013-08-12 Thread Gregory Nowak
On Mon, Aug 12, 2013 at 02:44:35PM -0600, Bob Proulx wrote: > I don't know anything about why you are having system crashes. But no > one else responded and so I decided to jump in. Thank you for doing so. I actually went ahead and opened bugs against openswan and bind9 after getting no responses

Re: bind9, openswan crashes wheezy VPS

2013-08-12 Thread Bob Proulx
Gregory Nowak wrote: > I have a VPS running a fresh install of wheezy, installed by me from > scratch (including kernel). Everything seems to be running fine, > except for bind9 and openswan which literally crash the vps as > explained below. I don't know anything about why you are having system c

Re: bind9 squeeze/oldstable

2013-05-18 Thread george cox
ticed the logs were empty then too. Thanks. - Original Message - From: Joe Sent: 05/18/13 08:31 AM To: debian-user@lists.debian.org Subject: Re: bind9 squeeze/oldstable On Sat, 18 May 2013 07:57:08 -0400 "george cox" wrote: > I found named-checkconf search-engining, and this

Re: bind9 squeeze/oldstable

2013-05-18 Thread Joe
On Sat, 18 May 2013 07:57:08 -0400 "george cox" wrote: > I found named-checkconf search-engining, and this found my bind > syntax error, yeah! > > Is there anything I can do about the logging issue? I was thinking of > doing a dist-upgrade to wheezy on my server, but could the logging > issue re

Re: bind9 squeeze/oldstable

2013-05-18 Thread george cox
I found named-checkconf search-engining, and this found my bind syntax error, yeah! Is there anything I can do about the logging issue? I was thinking of doing a dist-upgrade to wheezy on my server, but could the logging issue remain after the upgrade? Maybe I should just do a fresh install of

Re: Bind9 - help - wildcard priority fail.

2012-08-28 Thread Camaleón
On Mon, 27 Aug 2012 20:47:08 +0200, Ja wrote: > Hi, Hi, but please, no html posts, thanks :-) >   > I'm having problem with newest Bind9 (9.7.3). In version 9.6-ESV-R1 it > works fine. The problem is that wildcard records are taking priority to > more specific ones. (...) > When I ask Bind 9.6,

Re: Bind9 (9.7.4)

2011-11-08 Thread Pascal Hambourg
Hello, Chris Brennan a écrit : > > I was discussing a bind issue that I am experiencing w/ an acquaintance on > IRC this afternoon and he informed me that bind was updated to cover a > latent bug in the DNS message processing code that could allow certain > UPDATE requests to crash named. > >

Re: Bind9 (9.7.4)

2011-11-08 Thread Chris Brennan
On Tue, Nov 8, 2011 at 3:01 PM, Pascal Hambourg wrote: Hello, > > Chris Brennan a écrit : > > > > I was discussing a bind issue that I am experiencing w/ an acquaintance > on > > IRC this afternoon and he informed me that bind was updated to cover a > > latent bug in the DNS message processing co

Re: bind9 problems

2010-07-27 Thread Panayiotis Karabassis
Thanks to you all! I ended up using a local dhcp server. -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/4c4ec04d.1060...@gmail.com

Re: bind9 problems

2010-07-26 Thread Hanspeter Spalinger
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Am 26.07.10 15:35, schrieb Panayiotis Karabassis: > Sorry but I am somewhat of a newbie. > > Camaleón wrote: >> I'm not sure what are your goals with this step because the router >> hasn't to resolve local dns queries, but bind9 :-? >> > Don't co

Re: bind9 problems

2010-07-26 Thread Hanspeter Spalinger
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Am 26.07.10 15:17, schrieb Miles Fidelman: > Panayiotis Karabassis wrote: >> The DNS server seems to be working fine when accessed directly (i.e. >> through nslookup or by setting it as the primary nameserver for the >> computer manually throught /et

Re: bind9 problems

2010-07-26 Thread Camaleón
On Mon, 26 Jul 2010 16:35:08 +0300, Panayiotis Karabassis wrote: > Sorry but I am somewhat of a newbie. > > Camaleón wrote: >> I'm not sure what are your goals with this step because the router >> hasn't to resolve local dns queries, but bind9 :-? >> > Don't connected computers resolve dns que

Re: bind9 problems

2010-07-26 Thread Miles Fidelman
Panayiotis Karabassis wrote: Two thoughts come to mind: 1. see if you can traceroute the nameserver from somewhere off your local network (make sure to traceroute to port 53) The nameserver is not visible to the external world. Should I forward the port? 2. look at your router config - see

Re: bind9 problems

2010-07-26 Thread Panayiotis Karabassis
Miles Fidelman wrote: Perhaps a silly thought, but home routers are usually configured to access an external nameserver not one on the local network. Perhaps it can't reach the nameserver. I was thinking the same thing. Two thoughts come to mind: 1. see if you can traceroute the nameserver

Re: bind9 problems

2010-07-26 Thread Panayiotis Karabassis
Sorry but I am somewhat of a newbie. Camaleón wrote: I'm not sure what are your goals with this step because the router hasn't to resolve local dns queries, but bind9 :-? Don't connected computers resolve dns queries at the router? My goal is to make all computers on the local network automa

Re: bind9 problems

2010-07-26 Thread Camaleón
On Mon, 26 Jul 2010 14:56:53 +0300, Panayiotis Karabassis wrote: > I have setup a local DNS server on my home network (bind9 on debian > lenny). > > The DNS server seems to be working fine when accessed directly (i.e. > through nslookup or by setting it as the primary nameserver for the > compute

Re: bind9 problems

2010-07-26 Thread Miles Fidelman
Panayiotis Karabassis wrote: I have setup a local DNS server on my home network (bind9 on debian lenny). The DNS server seems to be working fine when accessed directly (i.e. through nslookup or by setting it as the primary nameserver for the computer manually throught /etc/resolv.conf). So

Re: bind9 problems

2010-07-26 Thread Manuel Hofer
Hi, are you maybe using your router as forwarder in your bind9 configuration? regards On Monday 26 July 2010 13:56:53 Panayiotis Karabassis wrote: > Hi! > > I have setup a local DNS server on my home network (bind9 on debian lenny). > > The DNS server seems to be working fine when accessed dir

Re: bind9 problems

2010-07-26 Thread Panayiotis Karabassis
Manuel Hofer wrote: Hi, are you maybe using your router as forwarder in your bind9 configuration? regards Thank you for your reply. No, I am using my ISP's nameservers. A little more info. I followed the article at [1]. Minus the stuff about chroot. If it would help I can post the related

Re: bind9 rndc reload problem (SOLVED)

2010-03-31 Thread Jari Fredriksson
On 1.4.2010 4:24, Jari Fredriksson wrote: > > I think this is how it is supposed to be in Debian. > > So. > 1. I change a zone file > 2. I add one to serial in the zone file > 3. I command "rndc reload" > 4. rndc connects to named, and all seems good > 5. changes do not show up :( > > Any ideas?

Re: bind9 rndc reload problem

2010-03-31 Thread David Parker
- Original Message - From: Jari Fredriksson Date: Wednesday, March 31, 2010 9:24 pm Subject: bind9 rndc reload problem To: Debian Users list > > When I command "rndc reload", this will be written to daemon.log > > Apr  1 04:13:17 spitfire named[19287]: received control > channel comma

Re: bind9 daemon owner

2009-04-01 Thread Glenn English
emmanuel segura wrote: vim /etc/default/bind9 man named Yup. But that wouldn't have solved the problem. Turned out to be the group, not the owner. Really didn't have much to do with bind itself... -- Glenn English g...@slsware.com -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debi

Re: bind9 daemon owner [solved]

2009-04-01 Thread ghe
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ghe wrote: > On one of my servers, bind9 has started running as root; it won't start > from init.d (permission denied when it tries to open its pid file -- > Webmin or the CL start it, but it runs as root); and it can't update > slave zones because it

Re: bind9+lenny+subdominio

2009-03-26 Thread Javier Barroso
2009/3/25 Yuniesky : > > Hola Colegas > ¿Como puedo delegar un subdominio a traves de mi dns? > > el caso es que estoy haciendo un test al bind9 sobre lenny en una maquina > de mi lan con un dominio diferente es decir un subdominio, en el server > agregue el subdominio al resolv.conf y trabaja perf

Re: bind9 crashing constantly in etch with no log output

2008-05-23 Thread Wm. Josiah Erikson
Also, when I build the package manually with apt-get source -b bind9, the resulting package has the same behavior. -Josiah Wm. Josiah Erikson wrote: Soon after I updated the recent SSL packages, I've had serious problems with bind9. All of my packages are up to date. I'm running etch on an

Re: bind9 crashing constantly in etch with no log output

2008-05-23 Thread Wm. Josiah Erikson
I just got a new error message as well: *** glibc detected *** malloc(): memory corruption (fast): 0x0813b5d0 *** Aborted (core dumped) If that means anything to anybody other than what it means to me, which is just that memory management isn't working right for some reason. As I said, I'd

Re: Bind9 can't start

2007-07-10 Thread Bob Proulx
Lars wrote: > I installed Bind9 on a DomU running etch > (2.6.18-4-xen-vserver-amd64), and bind couldn't start with default > configuration. > # /etc/init.d/bind9 restart > Stopping domain name service...: bindrndc: connect failed: > 127.0.0.1#953: connection refused > failed! > Starting domain na

Re: bind9 prevents external access

2007-03-30 Thread Jeff Dickison
On Wed, 21 Mar 2007, Justin Hartman wrote: Hi guys Very strange problem which I'm sure is pretty easy to fix - if you know how. I installed bind9 with lsb-base on a Debian Etch system. The problem is that as soon as bind9 is installed I can no longer ping or access external sites from the bind9

Re: bind9 prevents external access

2007-03-21 Thread Jeff D
On Thu, 22 Mar 2007, Justin Hartman wrote: Correction - /var/log/daemon.log does show an error relating to bind: Mar 22 06:16:46 justinhartman lwresd[2413]: starting BIND 9.3.4 Mar 22 06:16:46 justinhartman lwresd[2413]: found 1 CPU, using 1 worker Mar 22 06:16:46 justinhartman lwresd[2413]: n

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
Correction - /var/log/daemon.log does show an error relating to bind: Mar 22 06:16:46 justinhartman lwresd[2413]: starting BIND 9.3.4 Mar 22 06:16:46 justinhartman lwresd[2413]: found 1 CPU, using 1 worker thread Mar 22 06:16:46 justinhartman lwresd[2413]: loading configuration from '/etc/bind/lw

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
There are absolutely zero errors in the syslog file on either startup or when I do any look ups. On 3/22/07, Julian De Marchi <[EMAIL PROTECTED]> wrote: > On 3/22/07, Jeff D <[EMAIL PROTECTED]> wrote: > > Just out of curiosity, are you seeing any errors in your logs when you > do > > these look

Re: bind9 prevents external access

2007-03-21 Thread Jeff D
On Thu, 22 Mar 2007, Justin Hartman wrote: On 3/22/07, Jeff D <[EMAIL PROTECTED]> wrote: Just out of curiosity, are you seeing any errors in your logs when you do these look ups or when the server starts? Where exactly would I find the right log files to see this info? -- Regards Justin Hart

RE: bind9 prevents external access

2007-03-21 Thread Julian De Marchi
> On 3/22/07, Jeff D <[EMAIL PROTECTED]> wrote: > > Just out of curiosity, are you seeing any errors in your logs when you > do > > these look ups or when the server starts? > > Where exactly would I find the right log files to see this info? /var/log/syslog -- To UNSUBSCRIBE, email to [EMAI

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
On 3/22/07, Jeff D <[EMAIL PROTECTED]> wrote: Just out of curiosity, are you seeing any errors in your logs when you do these look ups or when the server starts? Where exactly would I find the right log files to see this info? -- Regards Justin Hartman PGP Key ID: 102CC123 -- To UNSUBSCRIBE,

RE: bind9 prevents external access

2007-03-21 Thread Julian De Marchi
> > On 3/21/07, Jeff D <[EMAIL PROTECTED]> wrote: > >> so with a clean bind install you still are not able to do lookups? > > > > Correct. Clean install > > > >> what does host google.com 127.0.0.1 give you? > > > > $ host google.com 127.0.0.1 > > ;; connection timed out; no servers could be reac

Re: bind9 prevents external access

2007-03-21 Thread Jeff D
On Wed, 21 Mar 2007, Justin Hartman wrote: On 3/21/07, Jeff D <[EMAIL PROTECTED]> wrote: so with a clean bind install you still are not able to do lookups? Correct. Clean install what does host google.com 127.0.0.1 give you? $ host google.com 127.0.0.1 ;; connection timed out; no servers

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
On 3/21/07, Jeff D <[EMAIL PROTECTED]> wrote: ok, check /etc/bind/named.conf , make sure you have : zone "." { type hint; file "/etc/bind/db.root"; }; Yes I do. I also have the following rdns entries directly below that: zone "127.in-addr.arpa" { type master; fi

Re: bind9 prevents external access

2007-03-21 Thread Jeff D
On Wed, 21 Mar 2007, Justin Hartman wrote: On 3/21/07, Jeff D <[EMAIL PROTECTED]> wrote: so with a clean bind install you still are not able to do lookups? Correct. Clean install what does host google.com 127.0.0.1 give you? $ host google.com 127.0.0.1 ;; connection timed out; no servers

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
Could this issue also not have something to do with the way in which my interfaces is setup? I'm thinking aloud here because I don't really know but in order for me to be able to setup two nameservers I was assigned a new IP range which I had to configure in the /etc/network/interfaces file. My

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
On 3/21/07, Jeff D <[EMAIL PROTECTED]> wrote: so with a clean bind install you still are not able to do lookups? Correct. Clean install what does host google.com 127.0.0.1 give you? $ host google.com 127.0.0.1 ;; connection timed out; no servers could be reached $ nslookup google.com 127

Re: bind9 prevents external access

2007-03-21 Thread Jeff D
On Wed, 21 Mar 2007, Justin Hartman wrote: Soma thanks for your input - by removing bind and playing with resolv.conf it is apparent that this file was causing certain issues. I have now installed resolvconf and after rebooting resolvconf configured only one line in resolv.conf file as follows:

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
Soma thanks for your input - by removing bind and playing with resolv.conf it is apparent that this file was causing certain issues. I have now installed resolvconf and after rebooting resolvconf configured only one line in resolv.conf file as follows: nameserver: 127.0.0.1 Prior to installing

Re: bind9 prevents external access

2007-03-21 Thread Soma R
On 3/21/07, Justin Hartman <[EMAIL PROTECTED]> wrote: On 3/21/07, Oliver Jato <[EMAIL PROTECTED]> wrote: > sorry, i forgot that you'll have to add "recursion yes;" to enable recursion. > the allow-recursion part was only to filter for whom your bind will resolve > recursive queries. you'll have

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
On 3/21/07, Oliver Jato <[EMAIL PROTECTED]> wrote: sorry, i forgot that you'll have to add "recursion yes;" to enable recursion. the allow-recursion part was only to filter for whom your bind will resolve recursive queries. you'll have to add both inside the "options { ... };" part of your named.

Re: bind9 prevents external access

2007-03-21 Thread Oliver Jato
Am Mittwoch, 21. März 2007 19:48 schrieb Justin Hartman: > On 3/21/07, Oliver Jato <[EMAIL PROTECTED]> wrote: > > you'll probably have to tell bind to use recursion for fetching adresses > > which are not in his authority. in options, set "allow-recursion { > > 127.0.0.1; };". if you want others on

Re: bind9 prevents external access

2007-03-21 Thread Justin Hartman
On 3/21/07, Oliver Jato <[EMAIL PROTECTED]> wrote: you'll probably have to tell bind to use recursion for fetching adresses which are not in his authority. in options, set "allow-recursion { 127.0.0.1; };". if you want others on your network to use your bind, too, also add "192.168.1/24;", for ex

Re: bind9 prevents external access

2007-03-21 Thread Oliver Jato
Am Mittwoch, 21. März 2007 19:10 schrieb Justin Hartman: > Very strange problem which I'm sure is pretty easy to fix - if you > know how. I installed bind9 with lsb-base on a Debian Etch system. The > problem is that as soon as bind9 is installed I can no longer ping or > access external sites from

Re: bind9 cache-only

2006-08-22 Thread Hugo Vanwoerkom
Nate Duehr wrote: On Aug 20, 2006, at 7:43 AM, Hugo Vanwoerkom wrote: Hi, In the (perhaps mistaken) notion that I am doing DNS lookups on sites that I always use and seem to take a long time, so would like a permanent cache, I installed bind9 on Sid. I changed Firehol and added the port

Re: bind9 cache-only

2006-08-21 Thread Nate Duehr
On Aug 20, 2006, at 7:43 AM, Hugo Vanwoerkom wrote: Hi, In the (perhaps mistaken) notion that I am doing DNS lookups on sites that I always use and seem to take a long time, so would like a permanent cache, I installed bind9 on Sid. I changed Firehol and added the port 53 server/client:

Re: bind9 cache-only

2006-08-20 Thread Hugo Vanwoerkom
Hugo Vanwoerkom wrote: As we study the manuals the opposition is gaining by hiding it all under a GUI... Still no luck caching-only, installing the world... H -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: bind9: high default SOA value

2006-05-03 Thread Matus UHLAR - fantomas
On 25.04.06 20:25, George Borisov wrote: > I have just finished configuring a new bind9 server on our network. :-) > > As a test I generated a report at www.dnsreport.com and it gave me the > following error message: > > --- > WARNING: Your SOA RETRY interval is : 86400 seconds. This seems very >

Re: bind9: high default SOA value

2006-04-25 Thread Roberto C. Sanchez
George Borisov wrote: > Hello, > > I have just finished configuring a new bind9 server on our network. :-) > > As a test I generated a report at www.dnsreport.com and it gave me the > following error message: > > --- > WARNING: Your SOA RETRY interval is : 86400 seconds. This seems very > high.

RE: bind9 in debian vserver wont start

2005-10-29 Thread Rabbie Zalaf
: Friday, October 28, 2005 3:07 AM To: Rabbie Zalaf Cc: debian-user@lists.debian.org Subject: Re: bind9 in debian vserver wont start     On 10/27/05, Rabbie Zalaf <[EMAIL PROTECTED]> wrote: Hey all,   I have read a few things on the net about setting up bind9 in a vserver but I jus

Re: bind9 in debian vserver wont start

2005-10-27 Thread Jeff D
Rabbie Zalaf wrote: Hey all, I have read a few things on the net about setting up bind9 in a vserver but I just cant get it to work. Can anyone help me get it running. When I do an: apt-get install bind9 bind9-host it works all ok but when I try to start bind9 I get the follo

Re: bind9 in debian vserver wont start

2005-10-27 Thread Meni Shapiro
On 10/27/05, Rabbie Zalaf <[EMAIL PROTECTED]> wrote: Hey all,   I have read a few things on the net about setting up bind9 in a vserver but I just cant get it to work. vserver as in virtual server? Can you bind port 53 for your copy of bind9??? check if you can configure your bind9

Re: Bind9/named/DNS help needed

2004-06-01 Thread David Piniella
mike wrote: Try having a workstation point directly at the DNS server that resolves your domain name. You should see the correct lookups. Then, if you point to any other DNS and still see the old lookups, then perhaps wait a few more days. he could also do dig @his.name.server.IP domain.he's.loo

Re: Bind9/named/DNS help needed

2004-05-31 Thread mike
On Fri, 28 May 2004 13:51:55 -0400, Adam Aube wrote > SnowWolf wrote: > > > The later is how the servers are setup on my registrar, and for a time > > they should correctly (but incorrect IP), but when the 43588 reached > > 0, it pulled the wrong information from _somewhere_ and now I'm back > > t

Re: Bind9/named/DNS help needed

2004-05-28 Thread Adam Aube
SnowWolf wrote: > The later is how the servers are setup on my registrar, and for a time > they should correctly (but incorrect IP), but when the 43588 reached > 0, it pulled the wrong information from _somewhere_ and now I'm back > to the old DNS settings When did you change the DNS servers

  1   2   >