[DNS] BIND 9.9.9-P8 issue

Daniel Rodrigues dro1976 at gmail.com
Mon Aug 21 08:33:43 UTC 2017


Hello guys,



We are facing to an important issue which is strongly annoying us on our
DNS resolvers. We saw our cache decrease and we got lot of
SERVFAIL/recursion during this period. The only way to solve it is to flush
cache or reboot BIND. Our version is 9.9.9-P8 running on RHEL 6.6. We
already got it 6 times in 1 week on different servers.

Here some logs when the problem appears :



named[10616]: database: warning: delete_node: dns_rbt_findnode(nsec):
partial match

named[10616]: general: warning: checkhints: unable to get root NS rrset
from cache: not found

general: info: sockmgr 0x7f4419f240f0: maximum number of FD events (64)
received



Below one link to see one cacti’s screen showing the performance:

https://drive.google.com/file/d/0B3pglqx0sbOiN3ZWQmM3MDdYOTQ
/view?usp=sharing




Do you have any idea to solve it definitively ? Is it an exploit bug ?

Thanks for you help.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20170821/1116c39e/attachment-0001.html>


More information about the bind-users mailing list