[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bind-users
Subject:    RE: bind-users Digest, Vol 1772, Issue 2
From:       houguanghua <houguanghua () hotmail ! com>
Date:       2014-02-26 13:49:51
Message-ID: BAY173-W30EE501FA020CB846673D8BB800 () phx ! gbl
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]

[Attachment #4 (text/plain)]

Thanks kevin. I'll try static-stub.

> Date: Tue, 25 Feb 2014 10:56:11 -0500
> From: Kevin Darcy <kcd@chrysler.com>
> To: bind-users@lists.isc.org
> Subject: Re: how to hidden the salve
> Message-ID: <530CBD1B.1060100@chrysler.com>
> Content-Type: text/plain; charset="iso-8859-1"; Format="flowed"
> 
> If you have zone-transfer permission, make a stealth slave. That, plus a 
> static-stub definition on your "local" server, and you're set.
> 
> Or, to simplify things even further, make the "local" server the stealth 
> slave (this makes some assumptions about your connectivity to the 
> authoritative nameservers for the zone).
> 
>                              - Kevin
> 
> On 2/25/2014 9:49 AM, houguanghua wrote:
> > Sorry.  My description isn't very clear.
> >
> > The local dns server isn't a stealth slave. I need a stealth slave and 
> > the local dns server can query it when all public NSs are out of service.
> >
> > Thanks!
> > Guanghua
> >
> >
> > > Date: Mon, 24 Feb 2014 13:41:03 -0500
> > > From: Kevin Darcy <kcd@chrysler.com>
> > > To: bind-users@lists.isc.org
> > > Subject: Re: how to hidden the salve
> > > Message-ID: <530B923F.8070409@chrysler.com>
> > > Content-Type: text/plain; charset="iso-8859-1"; Format="flowed"
> > >
> > > I guess I'm still not understanding your requirements. In my thinking,
> > > the local DNS server would *be* a stealth slave. Why are you 
> > considering
> > > these as 2 separate instances?
> > >
> > > - Kevin
> > >
> > > On 2/24/2014 9:56 AM, houguanghua wrote:
> > > > Dan,
> > > >
> > > > Yes, also-notify can hide the slave name server. But local dns server
> > > > can't know where is 'stealth' slave too.
> > > >
> > > > Thanks,
> > > > Guanghua
> > > >
> > > > ------------------------------------
> > > > Date: Fri, 21 Feb 2014 07:50:05 -0600
> > > > From: Daniel McDonald <dan.mcdonald@austinenergy.com>
> > > > To: Untitled <bind-users@lists.isc.org>
> > > > Subject: Re: bind-users Digest, Vol 1769, Issue 1
> > > > Message-ID: <CF2CB5AD.6AE8E%dan.mcdonald@austinenergy.com>
> > > > Content-Type: text/plain; charset="US-ASCII"
> > > >
> > > > On 2/21/14 3:39 AM, "houguanghua" <houguanghua@hotmail.com> wrote:
> > > >
> > > > > kevin,
> > > > >
> > > > > How does the local name server learn where is the 'stealth' slave?
> > > > For the
> > > > > 'stealth' slave isn't in the NS records.
> > > >
> > > > Also-notify directive. Either in an options stanza or a zone stanza.
> > > >
> > > > >
> > > > > thanks,
> > > > > Guanghua
> > > >
> > > > --
> > > > Daniel J McDonald, CISSP # 78281
> > > >
> > > >
> > > >
> > > > > Date: Thu, 20 Feb 2014 10:48:36 -0500
> > > > > From: Kevin Darcy <kcd@chrysler.com>
> > > > > To: bind-users@lists.isc.org
> > > > > Subject: Re: how to hidden the salve
> > > > > Message-ID: <530623D4.3000508@chrysler.com>
> > > > > Content-Type: text/plain; charset="iso-8859-1"; Format="flowed"
> > > > >
> > > > > A "stealth" slave has a full copy of the zone, is not published 
> > in the
> > > > > NS records, and can resolve names in the latest copy of the zone
> > > > that it
> > > > > transferred, even if all of the published NSes are down due to a 
> > DDoS
> > > > > attack.
> > > > >
> > > > > So, does that not meet the requirements?
> > > > >
> > > > > - Kevin
> > > > >
> > > > > On 2/20/2014 1:28 AM, houguanghua wrote:
> > > > > > "Stealth" slave doesn't fully meet the requirement. It's just 
> > part of
> > > > > > the requirement to not publish the slave name server in the NS
> > > > > > records. Further more, the 'stealth' slave is quired by local DNS
> > > > > > server only when all name servers in the NS records are out of
> > > > service
> > > > > > ( maybe in case of ddos attack).
> > > > > > Guanghua
> > > > > > ------------------------------
> > > > > > On 2/19/2014 11:54 AM, Kevin wrote:
> > > > > > Date: Wed, 19 Feb 2014 11:54:44 -0500
> > > > > > From: Kevin Darcy <kcd@chrysler.com>
> > > > > > To: bind-users@lists.isc.org
> > > > > > Subject: Re: how to modify the cache
> > > > > > Message-ID: 5304E1D4.5000303@chrysler.com
> > > > > > <mailto:5304E1D4.5000303@chrysler.com>
> > > > > >
> > > > > > Not a good solution. Even under "normal" circumstances, there 
> > will be
> > > > > > temporary bottlenecks, dropped packets, etc.. that will trigger
> > > > failover
> > > > > > and users will get different answers at different times. Not 
> > good for
> > > > > > support, maintainability, user experience/satisfaction, etc.
> > > > > >
> > > > > > If all you want is resilience, and you own/control the domain in
> > > > > > question, why not just slave it ("stealth" slave, i.e. you don't
> > > > need to
> > > > > > publish it in the NS records)?
> > > > > >
> > > > > > If you *don't* own/control the domain in question, what business
> > > > do you
> > > > > > have standing up a "fake" version of it in your own
> > > > infrastructure? Not
> > > > > > a best practice.
> > > > > >
> > > > > > - Kevin
> > > > > >
> > > > > > On 2/19/2014 4:51 AM, houguanghua wrote:
> > > > > > > Steven,
> > > > > > >
> > > > > > > Your solution is very good. It can forward the queries to
> > > > > > > the specified name servers first.
> > > > > > >
> > > > > > > But if the specified name server is enabled only when normal 
> > dns
> > > > query
> > > > > > > process is down. How to configure the local DNS server? The 
> > detailed
> > > > > > > scenario is descibed in below figure:
> > > > > > >
> > > > > > >
> > > > > >
> > > > > > --------------
> > > > > > | Root |
> > > > > > | nameServer |
> > > > > > / -------------
> > > > > > (2)/
> > > > > > /
> > > > > > ---------- ----------- -------------
> > > > > > | Client | __(1)____\ | Local | ___(3)_____\ |
> > > > > > Authority |
> > > > > > | Resolver | / | DNS Server | X / | DNS
> > > > > > Server |
> > > > > > ---------- ------------ -------------
> > > > > > \
> > > > > > \(4)
> > > > > > \
> > > > > > \ ------------
> > > > > > | Hidden |
> > > > > > | DNS Server |
> > > > > > ------------
> > > > > >
> > > > > > > Normally,
> > > > > > > 1) A internet user wants to access www.abc.com 
> > <http://www.abc.com
> > > > > > <http://www.abc.com/>>,
> > > > > > > a DNS request is sent to local DNS server
> > > > > > > 2) Local DNS server queries the root name server, the .com name
> > > > > > > server to get the Authority Name Server of abc.com
> > > > > > > 3) local DNS server queries the Authority name server, and gets
> > > > the IP
> > > > > > >
> > > > > > > But when the Authority name server is down, the internet 
> > user won't
> > > > > > > get the IP address. My solution is as follows:
> > > > > > > a) A hidden name server with low performance is deployed. When
> > > > > > > authority name server can't be accessed, local dns server will
> > > > access
> > > > > > > the hidden server.
> > > > > > > b)The hidden server is never used in normal situation. It act as
> > > > > > > a cold backup for authority name server.
> > > > > > > c) The zone file in the hidden server is the same as that
> > > > > > > configuration in the authority name server
> > > > > > > d) The hidden name server doesn't appear in the NS records
> > > > > > > of authority name server
> > > > > > >
> > > > > > > Btw, all above doesn't consider the cache in the local dns 
> > server.
> > > > > > >
> > > > > > >
> > > > > > > Best Regards,
> > > > > > > Guanghua
> > > > > > >
> > > > > > >
> > > > > > > > Date: Mon, 17 Feb 2014 09:09:13 +0000
> > > > > > > > Subject: Re: how to modify the cache
> > > > > > > > From: sjcarr@gmail.com
> > > > > > > > To: houguanghua@hotmail.com
> > > > > > > > CC: bind-users@lists.isc.org
> > > > > > > >
> > > > > > > > On 17 February 2014 01:17, houguanghua 
> > <houguanghua@hotmail.com>
> > > > > > wrote:
> > > > > > > > > I want to override the IP address of NS, for I want to 
> > use other
> > > > > > > authority
> > > > > > > > > DNS which isn't registered.
> > > > > > > >
> > > > > > > > For that you use forwarding. Create a zone statement for the
> > > > zone in
> > > > > > > > question and forward the queries to a different name server.
> > > > You don't
> > > > > > > > need to mess with the cache.
> > > > > > > >
> > > > > > > > 
> > https://mknowles.com.au/wordpress/2009/07/20/bind-forwarding-zone/
> > > > > > >
> >
> >
> >
> > _______________________________________________
> > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
> >
> > bind-users mailing list
> > bind-users@lists.isc.org
> > https://lists.isc.org/mailman/listinfo/bind-users
> 
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL: <https://lists.isc.org/pipermail/bind-users/attachments/20140225/e71ee1a6/attachment.html>
> 
> ------------------------------
> 
> _______________________________________________
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
> 
> End of bind-users Digest, Vol 1772, Issue 2
> *******************************************

 		 	   		  
[Attachment #5 (text/html)]

<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:΢ÈíÑźÚ
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Thanks kevin. I'll try \
static-stub.<BR><br>&gt; Date: Tue, 25 Feb 2014 10:56:11 -0500<br>&gt; From: Kevin \
Darcy &lt;kcd@chrysler.com&gt;<br>&gt; To: bind-users@lists.isc.org<br>&gt; Subject: \
Re: how to hidden the salve<br>&gt; Message-ID: \
&lt;530CBD1B.1060100@chrysler.com&gt;<br>&gt; Content-Type: text/plain; \
charset="iso-8859-1"; Format="flowed"<br>&gt; <br>&gt; If you have zone-transfer \
permission, make a stealth slave. That, plus a <br>&gt; static-stub definition on \
your "local" server, and you're set.<br>&gt; <br>&gt; Or, to simplify things even \
further, make the "local" server the stealth <br>&gt; slave (this makes some \
assumptions about your connectivity to the <br>&gt; authoritative nameservers for the \
zone).<br>&gt; <br>&gt;                              - Kevin<br>&gt; <br>&gt; On \
2/25/2014 9:49 AM, houguanghua wrote:<br>&gt; &gt; Sorry.  My description isn't very \
clear.<br>&gt; &gt;<br>&gt; &gt; The local dns server isn't a stealth slave. I need a \
stealth slave and <br>&gt; &gt; the local dns server can query it when all public NSs \
are out of service.<br>&gt; &gt;<br>&gt; &gt; Thanks!<br>&gt; &gt; Guanghua<br>&gt; \
&gt;<br>&gt; &gt;<br>&gt; &gt; &gt; Date: Mon, 24 Feb 2014 13:41:03 -0500<br>&gt; \
&gt; &gt; From: Kevin Darcy &lt;kcd@chrysler.com&gt;<br>&gt; &gt; &gt; To: \
bind-users@lists.isc.org<br>&gt; &gt; &gt; Subject: Re: how to hidden the \
salve<br>&gt; &gt; &gt; Message-ID: &lt;530B923F.8070409@chrysler.com&gt;<br>&gt; \
&gt; &gt; Content-Type: text/plain; charset="iso-8859-1"; Format="flowed"<br>&gt; \
&gt; &gt;<br>&gt; &gt; &gt; I guess I'm still not understanding your requirements. In \
my thinking,<br>&gt; &gt; &gt; the local DNS server would *be* a stealth slave. Why \
are you <br>&gt; &gt; considering<br>&gt; &gt; &gt; these as 2 separate \
instances?<br>&gt; &gt; &gt;<br>&gt; &gt; &gt; - Kevin<br>&gt; &gt; &gt;<br>&gt; &gt; \
&gt; On 2/24/2014 9:56 AM, houguanghua wrote:<br>&gt; &gt; &gt; &gt; Dan,<br>&gt; \
&gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; Yes, also-notify can hide the slave name \
server. But local dns server<br>&gt; &gt; &gt; &gt; can't know where is 'stealth' \
slave too.<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; Thanks,<br>&gt; &gt; &gt; \
&gt; Guanghua<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; \
------------------------------------<br>&gt; &gt; &gt; &gt; Date: Fri, 21 Feb 2014 \
07:50:05 -0600<br>&gt; &gt; &gt; &gt; From: Daniel McDonald \
&lt;dan.mcdonald@austinenergy.com&gt;<br>&gt; &gt; &gt; &gt; To: Untitled \
&lt;bind-users@lists.isc.org&gt;<br>&gt; &gt; &gt; &gt; Subject: Re: bind-users \
Digest, Vol 1769, Issue 1<br>&gt; &gt; &gt; &gt; Message-ID: \
&lt;CF2CB5AD.6AE8E%dan.mcdonald@austinenergy.com&gt;<br>&gt; &gt; &gt; &gt; \
Content-Type: text/plain; charset="US-ASCII"<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt; On 2/21/14 3:39 AM, "houguanghua" &lt;houguanghua@hotmail.com&gt; wrote:<br>&gt; \
&gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; kevin,<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; \
&gt; &gt; &gt; &gt; How does the local name server learn where is the 'stealth' \
slave?<br>&gt; &gt; &gt; &gt; For the<br>&gt; &gt; &gt; &gt; &gt; 'stealth' slave \
isn't in the NS records.<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; Also-notify \
directive. Either in an options stanza or a zone stanza.<br>&gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; thanks,<br>&gt; &gt; \
&gt; &gt; &gt; Guanghua<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; --<br>&gt; &gt; \
&gt; &gt; Daniel J McDonald, CISSP # 78281<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; Date: Thu, 20 Feb 2014 \
10:48:36 -0500<br>&gt; &gt; &gt; &gt; &gt; From: Kevin Darcy \
&lt;kcd@chrysler.com&gt;<br>&gt; &gt; &gt; &gt; &gt; To: \
bind-users@lists.isc.org<br>&gt; &gt; &gt; &gt; &gt; Subject: Re: how to hidden the \
salve<br>&gt; &gt; &gt; &gt; &gt; Message-ID: \
&lt;530623D4.3000508@chrysler.com&gt;<br>&gt; &gt; &gt; &gt; &gt; Content-Type: \
text/plain; charset="iso-8859-1"; Format="flowed"<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; \
&gt; &gt; &gt; &gt; A "stealth" slave has a full copy of the zone, is not published \
<br>&gt; &gt; in the<br>&gt; &gt; &gt; &gt; &gt; NS records, and can resolve names in \
the latest copy of the zone<br>&gt; &gt; &gt; &gt; that it<br>&gt; &gt; &gt; &gt; \
&gt; transferred, even if all of the published NSes are down due to a <br>&gt; &gt; \
DDoS<br>&gt; &gt; &gt; &gt; &gt; attack.<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; \
&gt; &gt; &gt; So, does that not meet the requirements?<br>&gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt; - Kevin<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; \
&gt; &gt; &gt; On 2/20/2014 1:28 AM, houguanghua wrote:<br>&gt; &gt; &gt; &gt; &gt; \
&gt; "Stealth" slave doesn't fully meet the requirement. It's just <br>&gt; &gt; part \
of<br>&gt; &gt; &gt; &gt; &gt; &gt; the requirement to not publish the slave name \
server in the NS<br>&gt; &gt; &gt; &gt; &gt; &gt; records. Further more, the \
'stealth' slave is quired by local DNS<br>&gt; &gt; &gt; &gt; &gt; &gt; server only \
when all name servers in the NS records are out of<br>&gt; &gt; &gt; &gt; \
service<br>&gt; &gt; &gt; &gt; &gt; &gt; ( maybe in case of ddos attack).<br>&gt; \
&gt; &gt; &gt; &gt; &gt; Guanghua<br>&gt; &gt; &gt; &gt; &gt; &gt; \
------------------------------<br>&gt; &gt; &gt; &gt; &gt; &gt; On 2/19/2014 11:54 \
AM, Kevin wrote:<br>&gt; &gt; &gt; &gt; &gt; &gt; Date: Wed, 19 Feb 2014 11:54:44 \
-0500<br>&gt; &gt; &gt; &gt; &gt; &gt; From: Kevin Darcy \
&lt;kcd@chrysler.com&gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; To: \
bind-users@lists.isc.org<br>&gt; &gt; &gt; &gt; &gt; &gt; Subject: Re: how to modify \
the cache<br>&gt; &gt; &gt; &gt; &gt; &gt; Message-ID: \
5304E1D4.5000303@chrysler.com<br>&gt; &gt; &gt; &gt; &gt; &gt; \
&lt;mailto:5304E1D4.5000303@chrysler.com&gt;<br>&gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; \
&gt; &gt; &gt; &gt; &gt; Not a good solution. Even under "normal" circumstances, \
there <br>&gt; &gt; will be<br>&gt; &gt; &gt; &gt; &gt; &gt; temporary bottlenecks, \
dropped packets, etc.. that will trigger<br>&gt; &gt; &gt; &gt; failover<br>&gt; &gt; \
&gt; &gt; &gt; &gt; and users will get different answers at different times. Not \
<br>&gt; &gt; good for<br>&gt; &gt; &gt; &gt; &gt; &gt; support, maintainability, \
user experience/satisfaction, etc.<br>&gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt; &gt; &gt; If all you want is resilience, and you own/control the domain \
in<br>&gt; &gt; &gt; &gt; &gt; &gt; question, why not just slave it ("stealth" slave, \
i.e. you don't<br>&gt; &gt; &gt; &gt; need to<br>&gt; &gt; &gt; &gt; &gt; &gt; \
publish it in the NS records)?<br>&gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt; &gt; &gt; If you *don't* own/control the domain in question, what \
business<br>&gt; &gt; &gt; &gt; do you<br>&gt; &gt; &gt; &gt; &gt; &gt; have standing \
up a "fake" version of it in your own<br>&gt; &gt; &gt; &gt; infrastructure? \
Not<br>&gt; &gt; &gt; &gt; &gt; &gt; a best practice.<br>&gt; &gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; - Kevin<br>&gt; &gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; On 2/19/2014 4:51 AM, houguanghua \
wrote:<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; Steven,<br>&gt; &gt; &gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; Your solution is very good. It can forward \
the queries to<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; the specified name servers \
first.<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; \
But if the specified name server is enabled only when normal <br>&gt; &gt; \
dns<br>&gt; &gt; &gt; &gt; query<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; process is \
down. How to configure the local DNS server? The <br>&gt; &gt; detailed<br>&gt; &gt; \
&gt; &gt; &gt; &gt; &gt; scenario is descibed in below figure:<br>&gt; &gt; &gt; &gt; \
&gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; --------------<br>&gt; &gt; &gt; &gt; &gt; &gt; \
| Root |<br>&gt; &gt; &gt; &gt; &gt; &gt; | nameServer |<br>&gt; &gt; &gt; &gt; &gt; \
&gt; / -------------<br>&gt; &gt; &gt; &gt; &gt; &gt; (2)/<br>&gt; &gt; &gt; &gt; \
&gt; &gt; /<br>&gt; &gt; &gt; &gt; &gt; &gt; ---------- ----------- \
-------------<br>&gt; &gt; &gt; &gt; &gt; &gt; | Client | __(1)____\ | Local | \
___(3)_____\ |<br>&gt; &gt; &gt; &gt; &gt; &gt; Authority |<br>&gt; &gt; &gt; &gt; \
&gt; &gt; | Resolver | / | DNS Server | X / | DNS<br>&gt; &gt; &gt; &gt; &gt; &gt; \
Server |<br>&gt; &gt; &gt; &gt; &gt; &gt; ---------- ------------ \
-------------<br>&gt; &gt; &gt; &gt; &gt; &gt; \<br>&gt; &gt; &gt; &gt; &gt; &gt; \
\(4)<br>&gt; &gt; &gt; &gt; &gt; &gt; \<br>&gt; &gt; &gt; &gt; &gt; &gt; \ \
------------<br>&gt; &gt; &gt; &gt; &gt; &gt; | Hidden |<br>&gt; &gt; &gt; &gt; &gt; \
&gt; | DNS Server |<br>&gt; &gt; &gt; &gt; &gt; &gt; ------------<br>&gt; &gt; &gt; \
&gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; Normally,<br>&gt; &gt; &gt; &gt; \
&gt; &gt; &gt; 1) A internet user wants to access www.abc.com <br>&gt; &gt; \
&lt;http://www.abc.com<br>&gt; &gt; &gt; &gt; &gt; &gt; \
&lt;http://www.abc.com/&gt;&gt;,<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; a DNS request \
is sent to local DNS server<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; 2) Local DNS server \
queries the root name server, the .com name<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; \
server to get the Authority Name Server of abc.com<br>&gt; &gt; &gt; &gt; &gt; &gt; \
&gt; 3) local DNS server queries the Authority name server, and gets<br>&gt; &gt; \
&gt; &gt; the IP<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; \
&gt; &gt; But when the Authority name server is down, the internet <br>&gt; &gt; user \
won't<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; get the IP address. My solution is as \
follows:<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; a) A hidden name server with low \
performance is deployed. When<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; authority name \
server can't be accessed, local dns server will<br>&gt; &gt; &gt; &gt; access<br>&gt; \
&gt; &gt; &gt; &gt; &gt; &gt; the hidden server.<br>&gt; &gt; &gt; &gt; &gt; &gt; \
&gt; b)The hidden server is never used in normal situation. It act as<br>&gt; &gt; \
&gt; &gt; &gt; &gt; &gt; a cold backup for authority name server.<br>&gt; &gt; &gt; \
&gt; &gt; &gt; &gt; c) The zone file in the hidden server is the same as that<br>&gt; \
&gt; &gt; &gt; &gt; &gt; &gt; configuration in the authority name server<br>&gt; &gt; \
&gt; &gt; &gt; &gt; &gt; d) The hidden name server doesn't appear in the NS \
records<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; of authority name server<br>&gt; &gt; \
&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; Btw, all above doesn't \
consider the cache in the local dns <br>&gt; &gt; server.<br>&gt; &gt; &gt; &gt; &gt; \
&gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; \
Best Regards,<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; Guanghua<br>&gt; &gt; &gt; &gt; \
&gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; \
&gt; &gt; Date: Mon, 17 Feb 2014 09:09:13 +0000<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; \
&gt; Subject: Re: how to modify the cache<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; \
From: sjcarr@gmail.com<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; To: \
houguanghua@hotmail.com<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; CC: \
bind-users@lists.isc.org<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt; &gt; &gt; &gt; &gt; On 17 February 2014 01:17, houguanghua <br>&gt; &gt; \
&lt;houguanghua@hotmail.com&gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; wrote:<br>&gt; &gt; \
&gt; &gt; &gt; &gt; &gt; &gt; &gt; I want to override the IP address of NS, for I \
want to <br>&gt; &gt; use other<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; \
authority<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; DNS which isn't \
registered.<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; \
&gt; &gt; &gt; For that you use forwarding. Create a zone statement for the<br>&gt; \
&gt; &gt; &gt; zone in<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; question and \
forward the queries to a different name server.<br>&gt; &gt; &gt; &gt; You \
don't<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; need to mess with the cache.<br>&gt; \
&gt; &gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; &gt; &gt; &gt; \
<br>&gt; &gt; https://mknowles.com.au/wordpress/2009/07/20/bind-forwarding-zone/<br>&gt; \
&gt; &gt; &gt; &gt; &gt; &gt;<br>&gt; &gt;<br>&gt; &gt;<br>&gt; &gt;<br>&gt; &gt; \
_______________________________________________<br>&gt; &gt; Please visit \
https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this \
list<br>&gt; &gt;<br>&gt; &gt; bind-users mailing list<br>&gt; &gt; \
bind-users@lists.isc.org<br>&gt; &gt; \
https://lists.isc.org/mailman/listinfo/bind-users<br>&gt; <br>&gt; -------------- \
next part --------------<br>&gt; An HTML attachment was scrubbed...<br>&gt; URL: \
&lt;https://lists.isc.org/pipermail/bind-users/attachments/20140225/e71ee1a6/attachment.html&gt;<br>&gt; \
<br>&gt; ------------------------------<br>&gt; <br>&gt; \
_______________________________________________<br>&gt; bind-users mailing \
list<br>&gt; bind-users@lists.isc.org<br>&gt; \
https://lists.isc.org/mailman/listinfo/bind-users<br>&gt; <br>&gt; End of bind-users \
Digest, Vol 1772, Issue 2<br>&gt; *******************************************<br><BR> \
</div></body> </html>



_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic