10-14-2008
You don't want to use a secondary nameserver in the system resolver as a form of conditional DNS lookups - the timeouts are too long, and that is not its intended purpose. The purpose is for one of having a backup for the situation when a primary is temporarily offline or unresponsive.
Setup bind with a forward zone for queries to internal.net that query your DNS server of choice. See: "A "forward zone" is a way to configure forwarding" in the BIND reference manual:
BIND 9 Administrator Reference Manual
Last edited by MrC; 10-15-2008 at 12:42 AM..
9 More Discussions You Might Find Interesting
1. Cybersecurity
Hi again guys,
It seems this is a global thing affecting all the DNS bind versions prior to July 28 2008. I have my work cut out for me very soon, I see at least a handful of servers in my list that either need to patching or upgrading.
How many of you guys are affected? Anybody successfully... (4 Replies)
Discussion started by: sparcguy
4 Replies
2. IP Networking
so we had bind 9.3.0...
we upgraded to 9.5.0 patch 1
we kept the exact same named.conf
now we have a problem that some DMZ server cant do lookups from our DNS slave anymore.
in the named.log we see things like this:
22-Jul-2008 16:05:04.694 security: info: client <our DMZ servers... (2 Replies)
Discussion started by: robsonde
2 Replies
3. Cybersecurity
Hi,
from my workplace we use a proxy to connect to the outside world, including external ssh servers.
The problem is that the server is seeing the connection coming from the proxy and knows nothing about the client behind it. The ssh connection itself works fine, but x-forwarding does not work as... (1 Reply)
Discussion started by: vampirodolce
1 Replies
4. UNIX and Linux Applications
Hello guys, can anyone help me with the below error I'm getting from bind9? I'm trying to make bind read all the zone info from openldap, I have already created the schema and I've put some info into the ldap. I have also tried to google the error with no success.
I'm aware there is an problem... (1 Reply)
Discussion started by: yered
1 Replies
5. UNIX for Advanced & Expert Users
Hi there,
I have the following problem.
I have a Debian server with bind9.
I can also use my ISP DNS server through the internet box (192.168.1.1).
I would like to fool my client workstation to a local machine when they query for one specific hostname within a domain.
I want to let the... (5 Replies)
Discussion started by: kokonut95
5 Replies
6. Solaris
I have configured a Bind9 DNS on a X4270 machine with Solaris10
I am excuting some repformance tests with DNSPERF tool and maximun CPU usage is 23%. I have seen with
prstat -L -p PID
that named process usses only 2 of the 8 available CPU at the same time although threads for all CPUs exist.... (2 Replies)
Discussion started by: parisph
2 Replies
7. UNIX for Dummies Questions & Answers
how can i set default permission for nslookup,
i have in my nslookup
timeout = 0 retry = 3 port = 53
but i want to set it to :
timeout = 2 retry = 2 port = 53
i'm using bind9 , where can i set the default timeout for it?
thanks in advance (0 Replies)
Discussion started by: prpkrk
0 Replies
8. UNIX for Dummies Questions & Answers
We're moving an app from a server in our domain to a server hosted by the vendor in their domain.
This app had it's own domain setup that we're authoritative for.
Do I need to create a new zone file? zone-vendor_com and set up the CNAME records in this file? Or if I can just edit the one I... (1 Reply)
Discussion started by: joeaverage
1 Replies
9. IP Networking
Hi all,
I've a litte problem to get rollerd running and signing my zones if the ZSK of my zones are near expiring or expired.
rollerd is running but do nothing
startet with:
/usr/bin/perl /usr/sbin/rollerd -rrfile /etc/bind/all.rollrec -directory /etc/bind -logfile /dev/stdout
... (1 Reply)
Discussion started by: xabbu
1 Replies
lwresd(1M) lwresd(1M)
NAME
lwresd - lightweight resolver daemon
SYNOPSIS
config-file] debuglevel] pid-file] ncpus] query-port] port] directory] user-id]
DESCRIPTION
The daemon provides name lookup services for clients that use the BIND 9 lightweight resolver library. It is essentially a stripped-down,
caching-only name server that answers queries using the BIND 9 lightweight resolver protocol rather than the DNS protocol.
listens for resolver queries on a UDP port on the IPv4 loopback interface, 127.0.0.1. This means that can only be used by processes run-
ning on the local machine. By default, UDP port number 921 is used for lightweight resolver requests and responses.
Incoming lightweight resolver requests are decoded by which then resolves them using the DNS protocol. When the DNS lookup completes,
encodes the answers from the name servers in the lightweight resolver format and returns them to the client that made the original request.
If the configuration file contains any entries, sends recursive DNS queries to those servers. This is similar to the use of forwarders in
a caching name server. If no entries are present, or if forwarding fails, resolves the queries autonomously starting at the root name
servers, using a compiled-in list of root-server hints.
Options
Use config-file as the configuration file. The default is
Set the debug level to
debuglevel. Debugging traces from become more verbose as the debug level increases.
Run in the foreground.
Run in the foreground and force all logging to standard error.
Write the daemon's process ID to
pid-file. The default is
Create ncpus worker threads to take advantage of multiple CPUs. By default, tries to determine the number of CPUs present and creates
one thread per CPU. If it cannot determine the number of CPUs, it creates a single worker thread.
Send DNS lookups to port number
query-port when querying name servers. This provides a way of testing the lightweight resolver daemon with a name server that
listens for queries on a nonstandard port number.
Listen for lightweight resolver queries on the
loopback interface using UDP port number port. The default is port 921.
Write memory usage statistics to standard output on exit.
This option is only of interest to BIND 9 developers and may be removed or changed in a future release.
Change root to
directory immediately after reading the configuration file (see chroot(2)).
Run as user-id, which is a user name or numeric ID that must be present in the password file. changes its user-id after it has carried
out any privileged operations, such as writing the process-ID file or binding a socket to a privileged port (typically any port
less than 1024).
Note
is a daemon for lightweight resolvers, not a lightweight daemon for resolvers.
AUTHOR
was developed by the Internet Systems Consortium (ISC).
FILES
Default resolver configuration file
Default process-id file
SEE ALSO
named(1M), chroot(2).
available online at
available from the Internet Systems Consortium at
BIND 9.3 lwresd(1M)