7 msgreg named.conf configuration file in bind 9.3.4
12 msgProviding local DNS service behind a cheap rout...
5 msghow to get a list like 'domains using this as n...
2 msghaving DNS problems with sites hosted at ns1.el...
5 msgDNS Server Host's Network DNS Settings

loss of masters over ipsec hoses bind
\ Matt LaPlante (21 Dec 2007)
. \ Barry Margolin (22 Dec 2007)
. . \ Matt LaPlante (22 Dec 2007)
. \ Mark Andrews (23 Dec 2007)
. \ Mark Andrews (24 Dec 2007)
. . \ Matt LaPlante (24 Dec 2007)
. . . \ Matt LaPlante (24 Dec 2007)
. . . . \ Matt LaPlante (9 Jan 2008)
. . . . . \ Adam Tkac (9 Jan 2008)
. . . . . . \ Matt LaPlante (10 Jan 2008)

21 msgoverride ttl=0
2 msgBIND8 was adding glue NS records to parent zones
2 msgSlaves not picking up when master is offline
12 msgUnable to get Zone transfer to work
3 msgmultiple answers from the same server
4 msgAccents in Bind 9.3.1. (Extended ascii)
1 msgRE: set up Reverse DNS zone
2 msgOT: set up Reverse DNS zone
2 msgBIND 9 utilities (dig, host, nslookup) error in...
6 msgsmall sibling glue records help
2 msgView Transfer
7 msgtips on debugging DNS
3 msgTrouble with reverse DNS
2 msgNewbie: How to add PTR records
Subject:loss of masters over ipsec hoses bind
Group:Bind-users
From:Matt LaPlante
Date:21 Dec 2007


 
I'm currently running Bind 9.4.1 (Ubuntu Gutsy). I have several zones
in master->slave setups, which normally works just fine. The other
day, however, I ran into an odd problem. A couple of the slave zones
generally update over an ipsec connected network. The ipsec
connection went away, and shortly thereafter bind royally wedged
itself, refusing to serve any data (including basic forward lookups)
and was not even responding to rndc restarts. It took me a good while
of restarting the system and poking around logs to decide to strace
the process, which eventually lead me to removing the ipsec-dependant
slave zones from the config. As soon as I did this, Bind became
stable again. Interestingly, zones which updated over public IP space
behaved fine, even if the master server was unreachable. It was only
zones that were trying to go over the down ipsec connection that hosed
the daemon.

This whole issue is logged in a bit more detail here, including output
from strace:
https://bugs.launchpad.net/ubuntu/+source/bind/+bug/177489

I can (apparently) reproduce this issue again with little difficulty,
so I'd be glad to help debug it.

-
Matt LaPlante




© 2004-2008 readlist.com