BIND & Delegation

Daniel Camacho dcamacho at saipan.com
Tue Dec 28 23:53:13 UTC 2004


Hi Peter,

phn at icke-reklam.ipsec.nu said:
> Daniel Camacho <dcamacho at saipan.com> wrote:
>
>> Peter,
>
>> I'm not delegating the same domain. In my example, the root is .tld and
>> I'm delegated the sld.tld. It is the domain.sld.tld that I'm having
>> difficulty delegating to other name servers. It was working before. It
>> just so happens that it won't work now. I just can't find the cause of
>> it.
>
> If you delegate "sld.tld." you cannot do anything with "domain.sld.tld",
> it
> has to be done with the server(s) "sld.tld." is authorative for.

I think I'm not making myself clear here. My apologies. What's happening
is there are a few domains that are delegated to me from the .xx TLD.
gov.xx, com.xx, etc.

My name servers are authoritative for all those domains as it should be.
Now, on my name servers, I'm delegating somesite.gov.xx to another ISP.
What's happening is that when I query other name servers, those
delegations don't show up. On some servers, when I query using dig. I get
the following:
(the result below is the real domain)

dig @ns2.lava.net www.crm.gov.mp A

; <<>> DiG 9.3.0 <<>> @ns2.lava.net www.crm.gov.mp A
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 11503
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;www.crm.gov.mp.                        IN      A

;; Query time: 639 msec
;; SERVER: 64.65.64.1#53(ns2.lava.net)
;; WHEN: Wed Dec 29 10:27:45 2004
;; MSG SIZE  rcvd: 32


...but when I do a +trace it gives the following:

dig @ns2.lava.net www.crm.gov.mp A +trace

; <<>> DiG 9.3.0 <<>> @ns2.lava.net www.crm.gov.mp A +trace
;; global options:  printcmd
.                       475971  IN      NS      M.ROOT-SERVERS.NET.
.                       475971  IN      NS      A.ROOT-SERVERS.NET.
.                       475971  IN      NS      B.ROOT-SERVERS.NET.
.                       475971  IN      NS      C.ROOT-SERVERS.NET.
.                       475971  IN      NS      D.ROOT-SERVERS.NET.
.                       475971  IN      NS      E.ROOT-SERVERS.NET.
.                       475971  IN      NS      F.ROOT-SERVERS.NET.
.                       475971  IN      NS      G.ROOT-SERVERS.NET.
.                       475971  IN      NS      H.ROOT-SERVERS.NET.
.                       475971  IN      NS      I.ROOT-SERVERS.NET.
.                       475971  IN      NS      J.ROOT-SERVERS.NET.
.                       475971  IN      NS      K.ROOT-SERVERS.NET.
.                       475971  IN      NS      L.ROOT-SERVERS.NET.
;; Received 436 bytes from 64.65.64.1#53(ns2.lava.net) in 210 ms

mp.                     172800  IN      NS      NS1.NIC.mp.
mp.                     172800  IN      NS      NS2.NIC.mp.
;; Received 104 bytes from 202.12.27.33#53(M.ROOT-SERVERS.NET) in 265 ms

www.crm.gov.mp.         86400   IN      NS      ns1.nic.net.mp.
www.crm.gov.mp.         86400   IN      NS      ns2.nic.net.mp.
;; Received 108 bytes from 202.128.29.2#53(NS1.NIC.mp) in 13 ms

crm.gov.mp.             43200   IN      NS      ns2.angilweb.net.
crm.gov.mp.             43200   IN      NS      ns1.angilweb.net.
;; Received 112 bytes from 202.128.28.3#53(ns1.nic.net.mp) in 0 ms

www.crm.gov.mp.         86400   IN      A       209.208.123.251
crm.gov.mp.             86400   IN      NS      ns1.angilweb.net.
crm.gov.mp.             86400   IN      NS      ns2.angilweb.net.
;; Received 128 bytes from 209.208.123.125#53(ns2.angilweb.net) in 216 ms

It seems that the delegations are not propagated properly to name servers
world-wide. I'm at a loss here. I hope you can provide some insights here.
Thanks.


Daniel

---------
>
>> I've indicated the problem in my first email via dig. Thanks for the
>> help.
>
> Welcome
>
>
> --
> Peter Håkanson
>         IPSec  Sverige      ( At Gothenburg Riverside )
>            Sorry about my e-mail address, but i'm trying to keep spam out,
> 	   remove "icke-reklam" if you feel for mailing me. Thanx.
>
>
>




More information about the bind-users mailing list