DNS servers wont resolve certain DNS names

phn at icke-reklam.ipsec.nu phn at icke-reklam.ipsec.nu
Tue Oct 21 06:02:23 UTC 2003


Mike Hale <mhale at toua.net> wrote:
> I run the DNS servers for toua.net. I have a user that complained that
> he can't resolve www.hardocp.com through our name servers. He was right.
> For some reason dig times out when resolving that address through our
> name servers but I can resolve it through the root servers. I checked m=
y
> root server list and it's up-to-date. I don't do any request forwards
> through another server, so I'm not sure why this may be happening. Any
> hints on where to look?

> Michael Hale
> Tohono O'odham Utility Authority (TOUA)
> Network Engineer
> phone: 1.520.383.5849
> email: mhale at toua.net
> web: http://www.toua.net/

hardocp.com has a few flaws which might be fatal :
1/
they have all the 4 nameservers at the end of the same link. Thus any loa=
ding
or disturbances will give them problems

2/=20
they have faultuy TTL on NS records and A records for same nameserver,
30minutes and 15 minutes. It stupid and wrong, and prevents other
nameservers to cache for any longer times.

(they don't know much about dns since they got "negatoive TTL" vs=20
"default TTL" backwards.)



--=20
Peter H=E5kanson        =20
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out=
,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


More information about the bind-users mailing list