BIND 9.11.4 dnstap not capturing updates

Tony Finch dot at dotat.at
Fri Aug 3 20:41:40 UTC 2018


> On 3 Aug 2018, at 20:08, Robert Edmonds <edmonds at mycre.ws> wrote:
> 
> dnstap doesn't have any `Type` values for an authoritative nameserver
> that is an initiator. For NOTIFY, we might need to add AUTH_CLIENT_QUERY
> and AUTH_CLIENT_RESPONSE in order to distinguish the initiator and
> responder in a NOTIFY transaction between two authoritative nameservers.

The other queries that auth servers make are to resolve the addresses of name servers that should receive NOTIFYs. I guess they go through the usual resolver machinery, so they are covered by existing dnstap probes, but I haven’t checked...

Tony.
-- 
f.anthony.n.finch  <dot at dotat.at>  http://dotat.at




More information about the bind-users mailing list