DLV dnssec setup

Wolfgang Rosenauer wrosenauer at gmail.com
Thu Jul 10 15:07:51 UTC 2014


On Thu, Jul 10, 2014 at 4:54 PM, Mark Andrews <marka at isc.org> wrote:
>
> Firstly upgrade.  You are out of date.

I currently run a distribution provided version which is pretty new
compared with most published Linux distributions but if it helps I
would do that as well.

> Secondly fix your firewall.  You need to allow through 4K DNS UDP
> messages.  You need to turn off whatever is blocking the bigger
> packets and you also need to allow through fragmented UDP packets.

ok, now this is probably tough.
There is no firewall involved which I could control. I'll see what can
be done. This server runs on virtuozzo/openvz at a hosting provider.


Thanks,
 Wolfgang


More information about the bind-users mailing list