Zone Transfer Request by Primary DNS Server

Mark.Andrews at nominum.com Mark.Andrews at nominum.com
Fri Apr 13 01:18:23 UTC 2001


	What makes you think it was the nameserver?

	"dig axfr jhuapl.edu @secondary-server" would have produced the
	same log messages, as would a number of other tools.

	Mark

> 
> Earlier today, I configured our secondary DNS servers with an ACL to further
> restrict who can perform zone transfers from our secondary DNS servers
> within our lab.  Additionally, I've also had logging set up on the servers
> to log any failed dynamic update attempts, failed zone transfers, etc.
> 
> One interesting thing I've noted since I put the ACL's into effect is a
> failed attempt by my primary DNS server to do a zone transfer from one of
> the secondaries.  Contents of the error log appear below.  What is troubling
> me is why the primary would be attempting to do a zone transfer in the first
> place when it is primary for all the zones.  Any insight anyone has into
> this would be greatly appreciated.
> 
> 
>  (acl)
> 12-Apr-2001 14:24:02.433 denied AXFR from [128.244.197.22].61286 for
> "jhuapl.edu
> " (acl)
> 
> 
> Thanks,
> 
> Bill
> 
--
Mark Andrews, Nominum Inc.
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark.Andrews at nominum.com


More information about the bind-users mailing list