debug SERVFAIL

Reindl Harald h.reindl at thelounge.net
Sun Oct 2 14:50:16 UTC 2016



Am 02.10.2016 um 16:46 schrieb Per olof Ljungmark:
> What is the best way to debug a SERVFAIL problem? I have tried to ramp
> up the trace level a lot but that did not return anything useful.
>
> It is only one zone in question, namely the PTR for our external subnet.
> What puzzles me the most is that a secondary on the same subnet answers
> just fine for thesame query. All forwards zones resolves good as well.
>
> BIND version is 9.10.4-P3

most likely some error in the zonefile, look at named logs

that the secondary answers is normal because if the master refuses to 
load a zone it never reaches the slave and start to fail there only when 
it expires before the error is fixed

hence master/slave while in most environemnts you could technically 
generate the identical zone-files on all nameservers but then with the 
same errors and so all would fail (in case of PTR and mailservers with 
horrible results)


More information about the bind-users mailing list