BIND 9.7 Serial Number Decrease Problem

McDonald, Dan Dan.McDonald at austinenergy.com
Mon Jun 6 20:20:26 UTC 2011


> -----Original Message-----
> From: bind-users-bounces+dan.mcdonald=austinenergy.com at lists.isc.org
>
[mailto:bind-users-bounces+dan.mcdonald=austinenergy.com at lists.isc.org]
> On Behalf Of Tony Finch
> Sent: Monday, June 06, 2011 2:43 PM
> To: Barry Finkel
> Cc: bind-users at lists.isc.org
> Subject: Re: BIND 9.7 Serial Number Decrease Problem

I think your root problem is trying to deal with active directory
integrated zones.  We stopped using them entirely when we found that
each domain controller maintains an individual SOA record with its own
serial number.  The serial numbers rapidly (and purposely) fall out of
sync, but active directory doesn't care as they use a different
replication method.

The only way that we could successfully interact from bind was to set up
a forward-only zone and try to cache the results.  When we found that
Active directory under windows 2000 was unable to maintain proper
synchronization, we switched to bind for all zones and haven't looked
back.


__
Daniel J McDonald, CCIE # 2495, CISSP # 78281
Austin Energy




More information about the bind-users mailing list