Forward by zone...

Kevin Darcy kcd at daimlerchrysler.com
Sat Nov 10 00:57:25 UTC 2001


If you can't do subdomain delegation, then you can't do per-domain forwarding.

However, you may be able to use "type stub" zones to get what you want...


- Kevin

"Chimento, Douglas" wrote:

> >> dig @172.26.11.100 sweet.dude.com. soa +norec:
>
> ; <<>> DiG 9.1.3 <<>> @172.26.11.100 sweet.dude.com. soa +norec
> ;; global options:  printcmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 26045
> ;; flags: qr aa ra; QUERY: 1, ANSWER: 1, AUTHORITY: 4, ADDITIONAL: 3
>
> ;; QUESTION SECTION:
> ;sweet.dude.com.                  IN      SOA
>
> ;; ANSWER SECTION:
> sweet.dude.com.           86400   IN      SOA     ipdbmro1.dude.com.
> dnsadmin.sweet.
> dude.com. 5116 21600 3600 604800 86400
>
> ;; AUTHORITY SECTION:
> sweet.dude.com.           86400   IN      NS      ipdbmro1.dude.com.
> sweet.dude.com.           86400   IN      NS      dns3mk201.sweet.dude.com.
> sweet.dude.com.           86400   IN      NS      dns3mr401.sweet.dude.com.
>
> ;; ADDITIONAL SECTION:
> dns3mk201.sweet.dude.com. 86400   IN      A       172.25.10.100
> dns3mr401.sweet.dude.com. 86400   IN      A       172.26.11.100
> ; <<>> DiG 9.1.3 <<>> @172.26.11.100 gslb.fmr.com. soa +norec
>
> I want to make  it clear that I CANNOT do sub-domain delegation.
> I hope this is clear.
> Thanks
>
> -----Original Message-----
> From: Michael Kjorling [mailto:michael at kjorling.com]
> Sent: Friday, November 09, 2001 2:46 PM
> To: BIND-Users
> Subject: RE: Forward by zone...
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On Nov 9 2001 13:13 -0500, Chimento, Douglas wrote:
>
> > Fine, You win
>
> Good, I have to say - it does make troubleshooting easier.
>
> > This is extactly what we have in PRODUCTION
> >
> > /snipped options/
> > zone "sweet.dude.com" {
> >         type forward;
> >         forward only;
> >         forwarders { 172.26.11.100; }; //SERVER B
> > };
>
> OK - so what do you get when you run:
>
>         dig @172.26.11.100 sweet.dude.com. soa +norec
>
> You should get an authorative response of exactly sweet.dude.com. SOA.
>
> Michael Kjörling
>
> - --
> Michael Kjörling  --  Programmer/Network administrator  ^..^
> PGP: 95f1 074d 336d f8f0 f297 6a5b 2aa3 7bfd 8a70 e33e   \/
> Internet: michael at kjorling.com -- FidoNet: 2:204/254.4
>
> "There is something to be said about not trying to be glamorous
> and popular and cool. Just be real -- and life will be real."
> (Joyce Sequichie Hifler, September 13 2001, www.hifler.com)
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.0.6 (GNU/Linux)
> Comment: Public key is at http://michael.kjorling.com/contact/pgp.html
>
> iD8DBQE77DJ9KqN7/Ypw4z4RAr8fAKCW7enrU4sK1y4v3m3wkikRdye1wACgqKT6
> 6a1tQPXlLpmraBC4RCXd6DA=
> =He5c
> -----END PGP SIGNATURE-----



More information about the bind-users mailing list