Spurious failures in a dynamically updated to a sub /24 reverse DNS domain

Tony Finch dot at dotat.at
Wed Dec 29 17:57:28 UTC 2021


Mirsad Goran Todorovac <mirsad.todorovac at alu.unizg.hr> wrote:
>
> I have recently implemented dynamic updates to a sub /24 reverse DNS
> domain, 193.198.186.192/27.
> I had upstream domain 192/27.186.198.193.in-addr.arpa. delegated from
> authoritative servers.
>
> However, something still isn't right. In some reverse PTR addresses, the
> resolver sees first redirection, and the second redirection, but somehow
> fails to connect them in a reverse lookup:

It looks to me like someone forgot to update the serial number on the zone
198.193.in-addr.arpa so your new delegation failed to propagate as it
should have,

The servers for 198.193.in-addr.arpa are:

dns1.carnet.hr
dns2.carnet.hr
ns.ripe.net

The first two know about the delegation for your zone
192/27.186.198.193.in-addr.arpa but ns.ripe.net does not.
This is the cause of the inconsistencies that you observed.

The SOA serial number for 198.193.in-addr.arpa is the same
2021052502 on all its nameservers.

Tony.
-- 
f.anthony.n.finch  <dot at dotat.at>  https://dotat.at/
the market alone does not distribute wealth or income fairly



More information about the bind-users mailing list