«tsig verify failure» only on some zones

Mark Andrews marka at isc.org
Thu Aug 19 01:00:19 UTC 2010

First thing.  Ensure that the nameservers are properly ntp synced.
This should get rid of mosr timing issues.

Secondly, for the failing zone run tcpdump on both ends and compare
the TCP payload of the packets.  They should be byte for byte
identical.  If they differ then the NAT box is fiddling with the


Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org

More information about the bind-users mailing list