Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #976 > unrolled thread

BIND9 - dig server fail

Started byalike <alike@ahgsa.com>
First post2012-01-15 20:42 +0100
Last post2012-01-18 08:09 +0100
Articles 20 on this page of 35 — 6 participants

Back to article view | Back to comp.os.linux.networking


Contents

  BIND9 - dig server fail alike <alike@ahgsa.com> - 2012-01-15 20:42 +0100
    Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-15 22:16 +0100
    Re: BIND9 - dig server fail Chris Davies <chris-usenet@roaima.co.uk> - 2012-01-15 21:18 +0000
      Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-16 10:33 +0100
        Re: BIND9 - dig server fail Chris Davies <chris-usenet@roaima.co.uk> - 2012-01-16 11:34 +0000
          Re: BIND9 - dig server fail alike <alike@ahgsa.com> - 2012-01-16 16:01 +0100
          Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-16 20:18 +0100
            Re: BIND9 - dig server fail Chris Davies <chris-usenet@roaima.co.uk> - 2012-01-16 22:15 +0000
            Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-17 08:53 +0100
              Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-17 09:16 +0100
                Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-18 08:03 +0100
                  Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-18 14:10 +0000
                    Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-18 15:55 +0100
                      Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-18 20:34 +0100
                        Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-19 08:17 +0100
                          Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-19 09:08 +0100
                            Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-20 08:43 +0100
                              Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-20 09:05 +0100
                              Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-20 22:38 +0100
                                Re: BIND9 - dig server fail Allodoxaphobia <knock_yourself_out@example.net> - 2012-01-21 16:32 +0000
                                  Re: BIND9 - dig server fail alike <alike@ahgsa.com> - 2012-01-22 20:08 +0100
                                    Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-22 22:52 +0100
                                      Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-23 07:50 +0100
                                        Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-23 21:06 +0100
                                          Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-24 07:17 +0100
                                            Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-24 07:54 +0100
                                            Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-24 09:09 +0100
                                              Re: BIND9 - dig server fail alike <alike@ahgsa.com> - 2012-01-24 19:25 +0100
                                              Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-26 07:21 +0100
                                                Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-26 08:10 +0100
                                Re: BIND9 - dig server fail alike <alike@ahgsa.com> - 2012-01-22 19:49 +0100
                                  Re: BIND9 - dig server fail Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-01-22 22:46 +0100
                                    Re: BIND9 - dig server fail alike <alike@asfas.com> - 2012-01-27 14:34 +0100
                Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-18 08:06 +0100
                  Re: BIND9 - dig server fail alike <alike@asas.net> - 2012-01-18 08:09 +0100

Page 1 of 2  [1] 2  Next page →


#976 — BIND9 - dig server fail

Fromalike <alike@ahgsa.com>
Date2012-01-15 20:42 +0100
SubjectBIND9 - dig server fail
Message-ID<jeva7u$b07$1@l01news1.ot.hr>
I have finally completed the main bind configuration.
Now when i run the gadmin tool i get status OK.
The zones are reloaded OK, resolv works but there i one problem.
When i dig my registered address i get servfail.

Google:
SERVFAIL means that the domain does exist and the root name servers have 
information on this domain, but that the authoritative name servers are 
not answering queries for this domain.

How to solve this ?

[toc] | [next] | [standalone]


#977

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-01-15 22:16 +0100
Message-ID<jevfnn$qne$2@saria.nerim.net>
In reply to#976
Hello,

alike a écrit :
> I have finally completed the main bind configuration.
> Now when i run the gadmin tool i get status OK.
> The zones are reloaded OK, resolv works but there i one problem.
> When i dig my registered address i get servfail.

What do you mean by your "registered address" ?
Is it supposed to be served authoritatively by your server ?

[toc] | [prev] | [next] | [standalone]


#978

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-01-15 21:18 +0000
Message-ID<1esbu8x0vb.ln2@news.roaima.co.uk>
In reply to#976
alike <alike@ahgsa.com> wrote:
> How to solve this ?

Provide some detail. For example, tell us what domain are you talking
about, so we can try it from "out here".

Chris

[toc] | [prev] | [next] | [standalone]


#979

Fromalike <alike@asas.net>
Date2012-01-16 10:33 +0100
Message-ID<jf0qta$puc$1@l01news1.ot.hr>
In reply to#978
On 01/15/2012 10:18 PM, Chris Davies wrote:
> alike<alike@ahgsa.com>  wrote:
>> How to solve this ?
>
> Provide some detail. For example, tell us what domain are you talking
> about, so we can try it from "out here".
>
> Chris
This are the main ones:

Named.conf.local
--------------------------------
zone "aisnet.com.hr" {
     type master;
     file "/etc/bind/db.aisnet.com.hr";
};
controls {
inet 127.0.0.1 {localhost;} keys {rndc_key;};
};


acl internals {
     127.0.0.0/8;
     10.0.0.0/24;
};
---------------------------------
db.aisnet.com.hr
---------------------------------
; aisnet.com.hr
$TTL    604800
$ORIGIN aisnet.com.hr
@       IN      SOA     ns1.aisnet.com.hr.  (
                      2006020201 ; Serial
                          604800 ; Refresh
                           86400 ; Retry
                         2419200 ; Expire
                          604800); Negative Cache TTL
;
@       IN      NS      ns1
         IN      A       192.168.1.110
ns1     IN      A       dns1.aisnet.com.hr
www     IN      A       192.168.1.110
---------------------------------
dns1.aisnet.com.hr --> 85.114.42.51
Local IP of my computer: 192.168.1.110

[toc] | [prev] | [next] | [standalone]


#980

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-01-16 11:34 +0000
Message-ID<giedu8x4v2.ln2@news.roaima.co.uk>
In reply to#979
alike <alike@asas.net> wrote:
> I have finally completed the main bind configuration.
> Now when i run the gadmin tool i get status OK.
> The zones are reloaded OK, resolv works but there i one problem.
> When i dig my registered address i get servfail.

> Named.conf.local
> --------------------------------
> zone "aisnet.com.hr" {
>     type master;
>     file "/etc/bind/db.aisnet.com.hr";
> };

> db.aisnet.com.hr
> ---------------------------------
> ; aisnet.com.hr
> $TTL    604800
> $ORIGIN aisnet.com.hr
> @       IN      SOA     ns1.aisnet.com.hr.  (
>                      2006020201 ; Serial
>                          604800 ; Refresh
>                           86400 ; Retry
>                         2419200 ; Expire
>                          604800); Negative Cache TTL
> ;
> @       IN      NS      ns1
>         IN      A       192.168.1.110
> ns1     IN      A       dns1.aisnet.com.hr
> www     IN      A       192.168.1.110


Firstly, there are two errors in this file.

1. An "A" record cannot resolve to a name, so your ns1 record is
invalid. Frankly, I'm amazed that bind9 will even run with this error.

2. Your SOA label should be an email address in dotted notation,
not what I assume is your NS hostname. So you might have @ IN SOA
hostmaster.aisnet.com.hr (implying a valid email address hostmaster *at*
aisnet.com.hr).

While you're experimenting I'd suggest you reduce the negative cache
ttl to something like 600 (10 minutes) and the retry down to 3600. Not
essential but can be helpful while you're changing the domain entries
around.


> dns1.aisnet.com.hr --> 85.114.42.51

Agreed. I can find that delegation, but there seems to be nothing
listening on that address.

* Have you allowed both UDP/53 and TCP/53 through your firewall?
* Is bind *really* running?

Chris

[toc] | [prev] | [next] | [standalone]


#981

Fromalike <alike@ahgsa.com>
Date2012-01-16 16:01 +0100
Message-ID<jf1e4o$13r$1@l01news1.ot.hr>
In reply to#980
On 01/16/2012 12:34 PM, Chris Davies wrote:
> alike<alike@asas.net>  wrote:
>> I have finally completed the main bind configuration.
>> Now when i run the gadmin tool i get status OK.
>> The zones are reloaded OK, resolv works but there i one problem.
>> When i dig my registered address i get servfail.
>
>> Named.conf.local
>> --------------------------------
>> zone "aisnet.com.hr" {
>>      type master;
>>      file "/etc/bind/db.aisnet.com.hr";
>> };
>
>> db.aisnet.com.hr
>> ---------------------------------
>> ; aisnet.com.hr
>> $TTL    604800
>> $ORIGIN aisnet.com.hr
>> @       IN      SOA     ns1.aisnet.com.hr.  (
>>                       2006020201 ; Serial
>>                           604800 ; Refresh
>>                            86400 ; Retry
>>                          2419200 ; Expire
>>                           604800); Negative Cache TTL
>> ;
>> @       IN      NS      ns1
>>          IN      A       192.168.1.110
>> ns1     IN      A       dns1.aisnet.com.hr
>> www     IN      A       192.168.1.110
>
>
> Firstly, there are two errors in this file.
>
> 1. An "A" record cannot resolve to a name, so your ns1 record is
> invalid. Frankly, I'm amazed that bind9 will even run with this error.
>
> 2. Your SOA label should be an email address in dotted notation,
> not what I assume is your NS hostname. So you might have @ IN SOA
> hostmaster.aisnet.com.hr (implying a valid email address hostmaster *at*
> aisnet.com.hr).
>
> While you're experimenting I'd suggest you reduce the negative cache
> ttl to something like 600 (10 minutes) and the retry down to 3600. Not
> essential but can be helpful while you're changing the domain entries
> around.
>
>
>> dns1.aisnet.com.hr -->  85.114.42.51
>
> Agreed. I can find that delegation, but there seems to be nothing
> listening on that address.
>
> * Have you allowed both UDP/53 and TCP/53 through your firewall?
> * Is bind *really* running?
>
> Chris
-------------------
I changed the resolv.conf file and reload the configuration.
Now i can get noerror when i run dig but when i check it at intodns.com 
i get some errors. Please chek it out:
http://www.intodns.com/aisnet.com.hr ( it takes some time to load )

[toc] | [prev] | [next] | [standalone]


#982

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-01-16 20:18 +0100
Message-ID<jf1t6o$1nvp$1@saria.nerim.net>
In reply to#980
Chris Davies a écrit :
> alike <alike@asas.net> wrote:
>> $TTL    604800
>> $ORIGIN aisnet.com.hr
>> @       IN      SOA     ns1.aisnet.com.hr.  (
>>                      2006020201 ; Serial
>>                          604800 ; Refresh
>>                           86400 ; Retry
>>                         2419200 ; Expire
>>                          604800); Negative Cache TTL
>> ;
>> @       IN      NS      ns1
>>         IN      A       192.168.1.110
>> ns1     IN      A       dns1.aisnet.com.hr
>> www     IN      A       192.168.1.110
> 
> 
> Firstly, there are two errors in this file.
> 
> 1. An "A" record cannot resolve to a name, so your ns1 record is
> invalid. Frankly, I'm amazed that bind9 will even run with this error.
> 
> 2. Your SOA label should be an email address in dotted notation,
> not what I assume is your NS hostname. So you might have @ IN SOA
> hostmaster.aisnet.com.hr (implying a valid email address hostmaster *at*
> aisnet.com.hr).

Actually an SOA record contains *both* a hostname and an e-mail addresse
in dotted notation. Here the address is missing.

3. The NS record(s) in the zone do not match the delegation in the
parent zone.

;; AUTHORITY SECTION:
aisnet.com.hr.          14400   IN      NS      dns2.aisnet.com.hr.
aisnet.com.hr.          14400   IN      NS      dns1.aisnet.com.hr.

;; ADDITIONAL SECTION:
dns1.aisnet.com.hr.     14400   IN      A       85.114.42.51
dns2.aisnet.com.hr.     14400   IN      A       85.114.42.52

4. A publicly accessible zone should not advertise private addresses
(192.168.1.110).

[toc] | [prev] | [next] | [standalone]


#983

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-01-16 22:15 +0000
Message-ID<h4keu8xvsk.ln2@news.roaima.co.uk>
In reply to#982
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote:
> Actually an SOA record contains *both* a hostname and an e-mail addresse
> in dotted notation. Here the address is missing.

Thank you Pascal. Once again I've leaped too quickly and you've had to
correct me. (I do know what I'm doing. Really!)

Cheers
Chris

[toc] | [prev] | [next] | [standalone]


#984

Fromalike <alike@asas.net>
Date2012-01-17 08:53 +0100
Message-ID<jf39ca$js1$1@l01news1.ot.hr>
In reply to#982
On 01/16/2012 08:18 PM, Pascal Hambourg wrote:
> Chris Davies a écrit :
>> alike<alike@asas.net>  wrote:
>>> $TTL    604800
>>> $ORIGIN aisnet.com.hr
>>> @       IN      SOA     ns1.aisnet.com.hr.  (
>>>                       2006020201 ; Serial
>>>                           604800 ; Refresh
>>>                            86400 ; Retry
>>>                          2419200 ; Expire
>>>                           604800); Negative Cache TTL
>>> ;
>>> @       IN      NS      ns1
>>>          IN      A       192.168.1.110
>>> ns1     IN      A       dns1.aisnet.com.hr
>>> www     IN      A       192.168.1.110
>>
>>
>> Firstly, there are two errors in this file.
>>
>> 1. An "A" record cannot resolve to a name, so your ns1 record is
>> invalid. Frankly, I'm amazed that bind9 will even run with this error.
>>
>> 2. Your SOA label should be an email address in dotted notation,
>> not what I assume is your NS hostname. So you might have @ IN SOA
>> hostmaster.aisnet.com.hr (implying a valid email address hostmaster *at*
>> aisnet.com.hr).
>
> Actually an SOA record contains *both* a hostname and an e-mail addresse
> in dotted notation. Here the address is missing.
>
> 3. The NS record(s) in the zone do not match the delegation in the
> parent zone.
>
> ;; AUTHORITY SECTION:
> aisnet.com.hr.          14400   IN      NS      dns2.aisnet.com.hr.
> aisnet.com.hr.          14400   IN      NS      dns1.aisnet.com.hr.
>
> ;; ADDITIONAL SECTION:
> dns1.aisnet.com.hr.     14400   IN      A       85.114.42.51
> dns2.aisnet.com.hr.     14400   IN      A       85.114.42.52
>
> 4. A publicly accessible zone should not advertise private addresses
> (192.168.1.110).
---------------------
$TTL    604800
$ORIGIN aisnet.com.hr
@       IN      SOA     ns1.aisnet.com.hr.  (
                      2006020201 ; Serial
                          604800 ; Refresh
                           86400 ; Retry
                         2419200 ; Expire
                          604800); Negative Cache TTL
;

aisnet.com.hr   14400   IN      NS      dns2.aisnet.com.hr
aisnet.com.hr   14400   IN      NS      dns1.aisnet.com.hr

dns2.aisnet.com.hr      14400   IN      A       85.114.42.51
dns1.aisnet.com.hr      14400   IN      A       85.114.42.52
------------------
Is this correct ?

When i make bind restart it will load ok but when i look at syslog i get 
error:

automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA
automatic empty zone: 0.1.1.0.0.2.IP6.ARPA
command channel listening on 127.0.0.1#953
command channel listening on ::1#953
zone 0.in-addr.arpa/IN: loaded serial 1
zone 127.in-addr.arpa/IN: loaded serial 1
zone 255.in-addr.arpa/IN: loaded serial 1
dns_rdata_fromtext: /etc/bind/db.aisnet.com.hr:8: near eol: unexpected 
end of input
zone aisnet.com.hr/IN: loading from master file 
/etc/bind/db.aisnet.com.hr failed: unexpected end of input
zone aisnet.com.hr/IN: not loaded due to errors.
zone localhost/IN: loaded serial 2
managed-keys-zone ./IN: loading from master file managed-keys.bind 
failed: file not found
managed-keys-zone ./IN: loaded serial 0
named[10130]: running
---------------------------------------

[toc] | [prev] | [next] | [standalone]


#985

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-01-17 09:16 +0100
Message-ID<jf3aog$27vr$1@saria.nerim.net>
In reply to#984
alike a écrit :
> On 01/16/2012 08:18 PM, Pascal Hambourg wrote:
>> Actually an SOA record contains *both* a hostname and an e-mail addresse
>> in dotted notation. Here the address is missing.
>
> $TTL    604800
> $ORIGIN aisnet.com.hr
> @       IN      SOA     ns1.aisnet.com.hr.  (
>                       2006020201 ; Serial
>                           604800 ; Refresh
>                            86400 ; Retry
>                          2419200 ; Expire
>                           604800); Negative Cache TTL
> ;
> 
> aisnet.com.hr   14400   IN      NS      dns2.aisnet.com.hr
> aisnet.com.hr   14400   IN      NS      dns1.aisnet.com.hr
> 
> dns2.aisnet.com.hr      14400   IN      A       85.114.42.51
> dns1.aisnet.com.hr      14400   IN      A       85.114.42.52
> ------------------
> Is this correct ?

Not yet, but almost.
The SOA record is still incomplete, see my comment above. Also you need
to add a final dot at the end of fully qualified domain names, otherwise
the base domain (origin) is appended.

dns2.aisnet.com.hr -> dns2.aisnet.com.hr.aisnet.com.hr.
dns2.aisnet.com.hr. -> ok

[toc] | [prev] | [next] | [standalone]


#986

Fromalike <alike@asas.net>
Date2012-01-18 08:03 +0100
Message-ID<jf5qqc$hun$1@l01news1.ot.hr>
In reply to#985
On 01/17/2012 09:16 AM, Pascal Hambourg wrote:
> alike a écrit :
>> On 01/16/2012 08:18 PM, Pascal Hambourg wrote:
>>> Actually an SOA record contains *both* a hostname and an e-mail addresse
>>> in dotted notation. Here the address is missing.
>>
>> $TTL    604800
>> $ORIGIN aisnet.com.hr
>> @       IN      SOA     ns1.aisnet.com.hr.  (
>>                        2006020201 ; Serial
>>                            604800 ; Refresh
>>                             86400 ; Retry
>>                           2419200 ; Expire
>>                            604800); Negative Cache TTL
>> ;
>>
>> aisnet.com.hr   14400   IN      NS      dns2.aisnet.com.hr
>> aisnet.com.hr   14400   IN      NS      dns1.aisnet.com.hr
>>
>> dns2.aisnet.com.hr      14400   IN      A       85.114.42.51
>> dns1.aisnet.com.hr      14400   IN      A       85.114.42.52
>> ------------------
>> Is this correct ?
>
> Not yet, but almost.
> The SOA record is still incomplete, see my comment above. Also you need
> to add a final dot at the end of fully qualified domain names, otherwise
> the base domain (origin) is appended.
>
> dns2.aisnet.com.hr ->  dns2.aisnet.com.hr.aisnet.com.hr.
> dns2.aisnet.com.hr. ->  ok
-----------------------------------------
zone 0.in-addr.arpa/IN: loaded serial 1
zone 127.in-addr.arpa/IN: loaded serial 1
zone 255.in-addr.arpa/IN: loaded serial 1
/etc/bind/db.aisnet.com.hr:3: SOA record not at top of zone 
(aisnet.com.hr.aisnet.com.hr)
zone aisnet.com.hr/IN: loading from master file 
/etc/bind/db.aisnet.com.hr failed: not at top of zone

zone aisnet.com.hr/IN: not loaded due to errors.
zone localhost/IN: loaded serial 2
managed-keys-zone ./IN: loading from master file managed-keys.bind 
failed: file not found
managed-keys-zone ./IN: loaded serial 0
named[10797]: running
//---------------------------------------------
$TTL    604800
$ORIGIN aisnet.com.hr
@       IN      SOA     ns1.aisnet.com.hr. hostmaster.aisnet.com.hr.(
                      2006020201 ; Serial
                          604800 ; Refresh
                           86400 ; Retry
                         2419200 ; Expire
                          604800); Negative Cache TTL
;

aisnet.com.hr	14400	IN	NS	dns2.aisnet.com.hr.
aisnet.com.hr	14400	IN	NS	dns1.aisnet.com.hr.

dns2.aisnet.com.hr	14400	IN	A	85.114.42.51
dns1.aisnet.com.hr	14400	IN	A	85.114.42.52
//--------------------------------------------------------------------------
SOA not at top of zone - how is bind reading this part ?
The line where SOA is defined should be OK. Do i need to add some 
additional part int db.aisnet.com.hr file ?

[toc] | [prev] | [next] | [standalone]


#989

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-01-18 14:10 +0000
Message-ID<jf6jsg$dc0$1@saria.nerim.net>
In reply to#986
alike a écrit :
> /etc/bind/db.aisnet.com.hr:3: SOA record not at top of zone
> (aisnet.com.hr.aisnet.com.hr)
> zone aisnet.com.hr/IN: loading from master file
> /etc/bind/db.aisnet.com.hr failed: not at top of zone

As I wrote, you must add a dot at the end of all instances of full domain
names, including in the $ORIGIN primitive, SOA and NS records. In short,
after all instances of aisnet.com.hr.

[toc] | [prev] | [next] | [standalone]


#990

Fromalike <alike@asas.net>
Date2012-01-18 15:55 +0100
Message-ID<jf6mg4$s47$1@l01news1.ot.hr>
In reply to#989
On 01/18/2012 03:10 PM, Pascal Hambourg wrote:
> alike a écrit :
>> /etc/bind/db.aisnet.com.hr:3: SOA record not at top of zone
>> (aisnet.com.hr.aisnet.com.hr)
>> zone aisnet.com.hr/IN: loading from master file
>> /etc/bind/db.aisnet.com.hr failed: not at top of zone
>
> As I wrote, you must add a dot at the end of all instances of full domain
> names, including in the $ORIGIN primitive, SOA and NS records. In short,
> after all instances of aisnet.com.hr.
Sorry i didnt know i have to put dots after all names.

Ok, now it has passed this part and this is the log file:

loading configuration from '/etc/bind/named.conf'
reading built-in trusted keys from file '/etc/bind/bind.keys'
using default UDP/IPv4 port range: [1024, 65535]
using default UDP/IPv6 port range: [1024, 65535]
listening on IPv6 interfaces, port 53
listening on IPv4 interface lo, 127.0.0.1#53
listening on IPv4 interface eth0, 192.168.1.110#53
generating session key for dynamic DNS
set up managed keys zone for view _default, file 'managed-keys.bind'
automatic empty zone: 254.169.IN-ADDR.ARPA
automatic empty zone: 2.0.192.IN-ADDR.ARPA
automatic empty zone: 100.51.198.IN-ADDR.ARPA
automatic empty zone: 113.0.203.IN-ADDR.ARPA
automatic empty zone: 255.255.255.255.IN-ADDR.ARPA
automatic empty zone: 
0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
automatic empty zone: 
1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
automatic empty zone: D.F.IP6.ARPA
automatic empty zone: 8.E.F.IP6.ARPA
automatic empty zone: 9.E.F.IP6.ARPA
automatic empty zone: A.E.F.IP6.ARPA
automatic empty zone: B.E.F.IP6.ARPA
automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA
automatic empty zone: 0.1.1.0.0.2.IP6.ARPA
command channel listening on 127.0.0.1#953
command channel listening on ::1#953
zone 0.in-addr.arpa/IN: loaded serial 1
zone 127.in-addr.arpa/IN: loaded serial 1
zone 255.in-addr.arpa/IN: loaded serial 1
zone aisnet.com.hr/IN: loaded serial 2006020201
zone localhost/IN: loaded serial 2
managed-keys-zone ./IN: loading from master file managed-keys.bind 
failed: file not found
managed-keys-zone ./IN: loaded serial 0
zone aisnet.com.hr/IN: sending notifies (serial 2006020201)
running
----------------------------------------------
Its interesting that intodns still doesn't find the nameservers

[toc] | [prev] | [next] | [standalone]


#991

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-01-18 20:34 +0100
Message-ID<jf76sh$kdg$1@saria.nerim.net>
In reply to#990
alike a écrit :
> 
> Ok, now it has passed this part and this is the log file:
> 
> loading configuration from '/etc/bind/named.conf'
> reading built-in trusted keys from file '/etc/bind/bind.keys'
> using default UDP/IPv4 port range: [1024, 65535]
> using default UDP/IPv6 port range: [1024, 65535]
> listening on IPv6 interfaces, port 53
> listening on IPv4 interface lo, 127.0.0.1#53
> listening on IPv4 interface eth0, 192.168.1.110#53
[...]
> zone aisnet.com.hr/IN: loaded serial 2006020201
[...]
> Its interesting that intodns still doesn't find the nameservers

The two declared nameserver addresses, 85.114.42.51 and 85.114.42.52,
are unreachable. No reply to ICMP echo (ping), traceroute, DNS request.
What are these adresses ? From the above log your DNS server address has
a private address, 192.168.1.110. How are they related ?

[toc] | [prev] | [next] | [standalone]


#992

Fromalike <alike@asas.net>
Date2012-01-19 08:17 +0100
Message-ID<jf8g1e$elk$1@l01news1.ot.hr>
In reply to#991
On 01/18/2012 08:34 PM, Pascal Hambourg wrote:
> alike a écrit :
>>
>> Ok, now it has passed this part and this is the log file:
>>
>> loading configuration from '/etc/bind/named.conf'
>> reading built-in trusted keys from file '/etc/bind/bind.keys'
>> using default UDP/IPv4 port range: [1024, 65535]
>> using default UDP/IPv6 port range: [1024, 65535]
>> listening on IPv6 interfaces, port 53
>> listening on IPv4 interface lo, 127.0.0.1#53
>> listening on IPv4 interface eth0, 192.168.1.110#53
> [...]
>> zone aisnet.com.hr/IN: loaded serial 2006020201
> [...]
>> Its interesting that intodns still doesn't find the nameservers
>
> The two declared nameserver addresses, 85.114.42.51 and 85.114.42.52,
> are unreachable. No reply to ICMP echo (ping), traceroute, DNS request.
> What are these adresses ? From the above log your DNS server address has
> a private address, 192.168.1.110. How are they related ?
----------------------------------
The main idea is to set something like dyndns.com because this is 
exactly what i need. I must be able to offer dynamic domain to my user.
Something like user.aisnet.com.hr.

Therefore i have registered aisnet.com.hr domain and two nameservers:
85.114.42.51 and 52. Those nameservers are registered by one domain 
provider.
---------------------------------
192.168.1.110 is the local ip of my computer and
this computer should act as dns server.
In my local network i have 5 computers and just one should act like dns 
server.
--------------------------------
db.aisnet.com.hr
****************
$TTL    604800
$ORIGIN aisnet.com.hr.
@       IN      SOA     ns1.aisnet.com.hr. hostmaster.aisnet.com.hr.(
                      2006020201 ; Serial
                          604800 ; Refresh
                           86400 ; Retry
                         2419200 ; Expire
                          604800); Negative Cache TTL
;

aisnet.com.hr.	14400	IN	NS	dns2.aisnet.com.hr.
aisnet.com.hr.	14400	IN	NS	dns1.aisnet.com.hr.

dns2.aisnet.com.hr.	14400	IN	A	85.114.42.51
dns1.aisnet.com.hr.	14400	IN	A	85.114.42.52

@		IN 	A	85.114.42.51 --> changed
--------------------------------------------
zone aisnet.com.hr/IN: loaded serial 2006020201
zone localhost/IN: loaded serial 2
managed-keys-zone ./IN: loading from master file managed-keys.bind 
failed: file not found
managed-keys-zone ./IN: loaded serial 0
zone aisnet.com.hr/IN: sending notifies (serial 2006020201)
running


[toc] | [prev] | [next] | [standalone]


#993

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-01-19 09:08 +0100
Message-ID<jf8j14$150f$1@saria.nerim.net>
In reply to#992
alike a écrit :
> 
> Therefore i have registered aisnet.com.hr domain and two nameservers:
> 85.114.42.51 and 52. Those nameservers are registered by one domain 
> provider.

What do you mean by "registered" ?
Who is operating those two nameservers ?

> ---------------------------------
> 192.168.1.110 is the local ip of my computer and
> this computer should act as dns server.

How is this nameserver related to the two others above ?
Private addresses are unreachable from the public internet.
Did you set up port forwarding from 85.114.42.51 or 85.114.42.52 to
192.168.1.110 ? Or is 192.168.1.110 used as a master (primary)
nameserver by 85.114.42.51 and 85.114.42.52 ?

[toc] | [prev] | [next] | [standalone]


#994

Fromalike <alike@asas.net>
Date2012-01-20 08:43 +0100
Message-ID<jfb5vr$bag$1@l01news1.ot.hr>
In reply to#993
On 01/19/2012 09:08 AM, Pascal Hambourg wrote:
> alike a écrit :
>>
>> Therefore i have registered aisnet.com.hr domain and two nameservers:
>> 85.114.42.51 and 52. Those nameservers are registered by one domain
>> provider.
>
> What do you mean by "registered" ?
> Who is operating those two nameservers ?
>
>> ---------------------------------------------------------
> 192.168.1.110 is the local ip of my computer and
> this computer should act as dns server.

> How is this nameserver related to the two others above ?
> Private addresses are unreachable from the public internet.
> Did you set up port forwarding from 85.114.42.51 or 85.114.42.52 to
> 192.168.1.110 ? Or is 192.168.1.110 used as a master (primary)
> nameserver by 85.114.42.51 and 85.114.42.52 ?

-------------------------------------------------------------
My local network is in range for 1.90 - 1.110.
The 192.168.1.110 is just local IP of my computer.
This computer should act as dns server.

85.114.42.51 and 52 are static IP addresses from my ISP and this 
addresses are registered as dns1.aisnet.com.hr, dns2.aisnet.com.hr


 > Who is operating those two nameservers ?
The "carnet" has put this two IP addresses into they dns server zones.
The carnet is research network: http://www.carnet.hr/en
------------------------------------------

[toc] | [prev] | [next] | [standalone]


#995

Fromalike <alike@asas.net>
Date2012-01-20 09:05 +0100
Message-ID<jfb78s$bna$1@l01news1.ot.hr>
In reply to#994
On 01/20/2012 08:43 AM, alike wrote:
> On 01/19/2012 09:08 AM, Pascal Hambourg wrote:
>> alike a écrit :
>>>
>>> Therefore i have registered aisnet.com.hr domain and two nameservers:
>>> 85.114.42.51 and 52. Those nameservers are registered by one domain
>>> provider.
>>
>> What do you mean by "registered" ?
>> Who is operating those two nameservers ?
>>
>>> ---------------------------------------------------------
>> 192.168.1.110 is the local ip of my computer and
>> this computer should act as dns server.
>
>> How is this nameserver related to the two others above ?
>> Private addresses are unreachable from the public internet.
>> Did you set up port forwarding from 85.114.42.51 or 85.114.42.52 to
>> 192.168.1.110 ? Or is 192.168.1.110 used as a master (primary)
>> nameserver by 85.114.42.51 and 85.114.42.52 ?
>
> -------------------------------------------------------------
> My local network is in range for 1.90 - 1.110.
> The 192.168.1.110 is just local IP of my computer.
> This computer should act as dns server.
>
> 85.114.42.51 and 52 are static IP addresses from my ISP and this
> addresses are registered as dns1.aisnet.com.hr, dns2.aisnet.com.hr
>
>
>  > Who is operating those two nameservers ?
> The "carnet" has put this two IP addresses into they dns server zones.
> The carnet is research network: http://www.carnet.hr/en
> ------------------------------------------
I have contacted the carnet and my register and they both think that 
there is a problem in configuration. I got answer that 
dns1.aisnet.com.hr is in the NS and that aisnet.com.hr domain is active.

So, it look like something is blocking the dns1.aisnet.com.hr or we have 
to change the configuration.

As far as i understand... my computer (dns server) is set to 
192.168.1.110 . In bind configuration we have set the dns1.aisnet.com.hr 
and dns2.aisnet.com.hr as two addresses of the name servers. So now we 
have to find a way how to combine/process local IP and dns ip's .

[toc] | [prev] | [next] | [standalone]


#996

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-01-20 22:38 +0100
Message-ID<jfcmsp$2md0$1@saria.nerim.net>
In reply to#994
alike a écrit :
> 
> My local network is in range for 1.90 - 1.110.
> The 192.168.1.110 is just local IP of my computer.
> This computer should act as dns server.
> 
> 85.114.42.51 and 52 are static IP addresses from my ISP and this 
> addresses are registered as dns1.aisnet.com.hr, dns2.aisnet.com.hr
> 
>> Who is operating those two nameservers ?
> The "carnet" has put this two IP addresses into they dns server zones.
> The carnet is research network: http://www.carnet.hr/en

This is just the delegation and does not answer my question : who is
operating the two hosts at addresses 85.114.42.51 and 52 and how are
they (supposed to be) related to your private DNS server ?

[toc] | [prev] | [next] | [standalone]


#997

FromAllodoxaphobia <knock_yourself_out@example.net>
Date2012-01-21 16:32 +0000
Message-ID<slrnjhlq34.7eu.knock_yourself_out@shell.config.com>
In reply to#996
On Fri, 20 Jan 2012 22:38:29 +0100, Pascal Hambourg wrote:
> alike a écrit :
>> 
>> My local network is in range for 1.90 - 1.110.
>> The 192.168.1.110 is just local IP of my computer.
>> This computer should act as dns server.
>> 
>> 85.114.42.51 and 52 are static IP addresses from my ISP and this 
>> addresses are registered as dns1.aisnet.com.hr, dns2.aisnet.com.hr
>> 
>>> Who is operating those two nameservers ?
>> The "carnet" has put this two IP addresses into they dns server zones.
>> The carnet is research network: http://www.carnet.hr/en
>
> This is just the delegation and does not answer my question : who is
> operating the two hosts at addresses 85.114.42.51 and 52 and how are
> they (supposed to be) related to your private DNS server ?

What was revealed when you did a `whois` on either of those IPs?


[quoting and attribution was mangled before I showed up.]

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.os.linux.networking


csiph-web