Cannot resolve outside my TLD - all others give SERVFAIL

Matus UHLAR - fantomas uhlar at fantomas.sk
Thu Apr 29 06:54:48 UTC 2010


On 28.04.10 16:55, Chris C wrote:
> This instance is used as a caching resolver with blacklists.  The
> blacklists are fed what is basically a null.zone file.

how do you implement blacklists? show me example of one blacklisted zone
configuration - not the zone file but the part of named.conf.

> IE.
  ^^^
What's this? does it appear in each blacklisted zone file?

> $TTL    86400   ; one day
> 
> @       IN      SOA     dnsbl0.xxx.xxx.      hostmaster.xxx.xxx. (
[...]
> *		IN      A       127.0.0.3
> 
> 
> There are approx. 172K zones for the blacklist.
> 
> Recently the system would give out SERVFAIL for all queries outside my
> TLD.  Anything inside my TLD works fine.

aren't you running out of memory?

> If I drop the blacklists (say to 50K), it works fine.  I am trying to
> find that magic number in which the failures start to occur, but the
> daemon takes about 15-20 minutes for a restart.  I will post that once
> obtained.

might be a memory problem.
-- 
Matus UHLAR - fantomas, uhlar at fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Windows 2000: 640 MB ought to be enough for anybody



More information about the bind-users mailing list