after you slap me, help me! dns w/cablemodem & dhcp...

Kevin Darcy kcd at daimlerchrysler.com
Thu May 10 20:41:21 UTC 2001


First of all, you're using DHCP but do you have a *static* address? If you
don't have a static address, then it's going to be difficult if not impossible
to host your own DNS information. I've never dealt with GraniteCanyon, but
I thought they just provided a free *slave* service (someone please correct me
if I'm wrong). Trouble is, if the address of the master is subject to change
with little or no notice, GraniteCanyon or anyone else is going to have a heck
of a time being a slave to it. Not only that, but there could be security
implications -- what if the box that gets your address feeds a spoofed version
of quantifier.org to GraniteCanyon before you get a chance to inform
GraniteCanyon of the address change? To be safe, you should TSIG-authenticate
your zone transfers. But I don't know if GraniteCanyon supports that.

Secondly, I thought @home didn't want people running servers on their network.
If so, they may be blocking inbound DNS queries (conceivably they could even
block *outgoing* non-recursive queries, if they wanted to spend the cycles to
look at the RD bit of every outgoing DNS packet). You might want to verify
this.This could make hosting DNS very difficult, although of course many
things are possible through the magic of tunnelling (yuck).


- Kevin

ken wrote:

> NEW to DNS, and trying, trying hard!
>
> FACT: Me--rh7, 2.4.3 kernel, @home cablemodem w\dhcp...
> This means my resolv.conf file gets written to with their domain name
> servers. RH as it is in my incarnation, has bind running as a caching-only
> ns.
>
> It's using named.local and named.ca...
>
> I bought a domain name, quantifier.org. I want my box to serve pages for
> quantifier.org. Currently all user directories work and apache is running.
> As is named. AS I currently understand, I must run DNS too so my IP
> (24.4.222.73) resolves to quantifer.org.
>
> I have looked at granitecanyon.com and honestly was confused when trying to
> create the RR records because I saw nowhere to put my IP. If I can use two
> "other" nameservers and let them do the work, then I don't need it, right?
>
> If I get them to do it, I don't know how to write the RR so that addresses
> resolve to me at 24.4.222.73.
>
> a.) I believe I will have to tell Apache via virtual hosts. That road I'll
> walk after quantifier becomes good.
>
> b.) I know I still have to do sendmail.
>
> WHAT I NEED HELP ON is direction, and not RTFM. I have those bastards
> strewn about me like paper for a toilet-training puppy.
>
> If anybody has this conquered, please contact me. Once I figure this mess
> out I guarantee to pass it on.
>
> Ken
> schlitzllama at home.com





More information about the bind-users mailing list