how to see ALL NS records in a zone file with dig

M. Meadows sun-guru at live.com
Mon Nov 15 18:35:53 UTC 2010


Jay,
 
     I see what you're saying. I was missing the difference in the feedback from the recurse / no recurse options. Makes sense. Thanks very much for the excellent help!
 
Marty

 
> Date: Mon, 15 Nov 2010 10:57:40 -0600
> From: jay-ford at uiowa.edu
> To: sun-guru at live.com
> Subject: RE: how to see ALL NS records in a zone file with dig
> 
> On Mon, 15 Nov 2010, M. Meadows wrote:
> > Thanks for the reply Jay. Does that work for you? It doesn't work for me.
> 
> Yep, it works for me. Here's an example for zone healthcare.uiowa.edu with
> the query answered by an authoritative server for the parent (uiowa.edu).
> 
> The query with recursion disabled shows dns-cb returning its view as the
> parent above the uiowa.edu -> healthcare.uiowa.edu delegation cut:
> 
> jnford at seatpost: dig +norec +nostats -t ns healthcare.uiowa.edu @dns-cb.uiowa.edu
> 
> ; <<>> DiG 9.7.1-P2 <<>> +norec +nostats -t ns healthcare.uiowa.edu @dns-cb.uiowa.edu
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31651
> ;; flags: qr ra; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 2
> 
> ;; QUESTION SECTION:
> ;healthcare.uiowa.edu. IN NS
> 
> ;; AUTHORITY SECTION:
> healthcare.uiowa.edu. 86400 IN NS dns1.uihealthcare.com.
> healthcare.uiowa.edu. 86400 IN NS dns2.uihealthcare.com.
> 
> ;; ADDITIONAL SECTION:
> dns1.uihealthcare.com. 2305 IN A 129.255.116.10
> dns2.uihealthcare.com. 1178 IN A 129.255.116.11
> 
> It returns no answers, just a referral to what it's been told the servers are
> for healthcare.uiowa.edu.
> 
> 
> The query with recursion enabled shows dns-cb returning the information it
> has cached for healthcare.uiowa.edu:
> 
> jnford at seatpost: dig +nostats -t ns healthcare.uiowa.edu @dns-cb.uiowa.edu
> 
> ; <<>> DiG 9.7.1-P2 <<>> +nostats -t ns healthcare.uiowa.edu @dns-cb.uiowa.edu
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29488
> ;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 0
> 
> ;; QUESTION SECTION:
> ;healthcare.uiowa.edu. IN NS
> 
> ;; ANSWER SECTION:
> healthcare.uiowa.edu. 3283 IN NS hc-dc3.healthcare.uiowa.edu.
> healthcare.uiowa.edu. 3283 IN NS hc-dc4.healthcare.uiowa.edu.
> healthcare.uiowa.edu. 3283 IN NS hc-dc5.healthcare.uiowa.edu.
> healthcare.uiowa.edu. 3283 IN NS hc-dc1.healthcare.uiowa.edu.
> healthcare.uiowa.edu. 3283 IN NS hc-dc2.healthcare.uiowa.edu.
> 
> It returns answers rather than a referral.
> 
> Note that in neither cases is the response authoritative, because dns-cb
> doesn't hold authority over the healthcare.uiowa.edu zone. It has the
> configured hints about how to get to the authoritative servers, & it will
> cache the server list from the authoritative servers.
> 
> Is that not the type of behavior you're getting with your servers?
> 
> ________________________________________________________________________
> Jay Ford, Network Engineering Group, Information Technology Services
> University of Iowa, Iowa City, IA 52242
> email: jay-ford at uiowa.edu, phone: 319-335-5555, fax: 319-335-2951
 		 	   		  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20101115/71936391/attachment.html>


More information about the bind-users mailing list