How to set the Slave DNS Server ?

Kevin Darcy kcd at daimlerchrysler.com
Wed Nov 20 01:20:16 UTC 2002


Are you sure you have no "allow-query" restrictions on the master? Looks like
you're denying queries from your own slave nameserver.


- Kevin

Kevin Chan wrote:

> Hi Kevin and all,
>
> Error messages from Primary DNS as before:
>
> Nov 16 03:25:38 ns1 named[3343]: client XXX.XXX.XXX.58#1031: query
> 'XXX.XXX.XXX.i
> n-addr.arpa/IN' denied
> Nov 16 03:48:30 ns1 named[3343]: client XXX.XXX.XXX.60#1031: query 'tony.co
> m/IN' denied
>
> Error messages from Secondary DNS as below:
>
> Nov 16 03:54:56 ns2 named[3041]: zone XXX.XXX.XXX.in-addr.arpa/IN: refresh:
> unexp
> ected rcode (REFUSED) from master XXX.XXX.XXX.57#53
> Nov 16 04:17:48 ns2 named[3041]: zone tony.com/IN: refresh: unexpected rcod
> e (REFUSED) from master XXX.XXX.XXX.57#53
>
> I was enable the ipchains/iptables running on these server but I open the
> port 53 from "setup" command.  Also, I can't use the these DNS Server if I
> set the port 53 disable, so that I think I was open the port 53 on both
> server already.
>
> Please teach me what's wrong on those DNS Server....thanks !
>
> Best regards,
> Kevin
>
> > Kevin Darcy wrote:
> >
> >
> > Kevin Chan wrote:
> >
> > > Dear all,
> > >
> > > After I change the setting as below, the Secondary DNS Server seem like
> > > doesn't work as secondary.  Because after I add the new server IP on
> "zone
> > > name" and "zone IP" files in Primary DNS Server for 3 hours, the
> Secondary
> > > DNS Server is haven't update the record.
> > >
> > > Can anyone show / help me to solve this problem ?
> > >
> > > Thanks and regards,
> > > Kevin Chan
> >
> > You forgot to change the zone type for the "kevin.com" zone.
> >
> > The XXX.XXX.XXX.in-addr.arpa zone should be slaving properly, though.
> Isn't
> > it? If it isn't, check the logs for errors (in fact, if you had checked
> the
> > logs for errors, you should have noticed that "kevin.com" wasn't loading
> > properly; scrupulously checking the logs is a good habit to get into).
> >
> >
> > - Kevin
> >
> >



More information about the bind-users mailing list