Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 20 Apr 2003 01:03:53 +0900
From:      JINMEI Tatuya / =?ISO-2022-JP?B?GyRCP0BMQEMjOkgbKEI=?= <jinmei@isl.rdc.toshiba.co.jp>
To:        Jeremy Chadwick <freebsd@jdc.parodius.com>
Cc:        freebsd-net@freebsd.org
Subject:   Re: BIND-8/9 interface bug? Or is it FreeBSD?
Message-ID:  <y7v4r4ucw46.wl@ocean.jinmei.org>
In-Reply-To: <20030419064801.GA11635@parodius.com>
References:  <20030418201645.GA77986@parodius.com> <1050703016.604363.667.nullmailer@cicuta.babolo.ru> <20030418234119.GA85777@parodius.com> <y7v65pbcbwc.wl@ocean.jinmei.org> <20030419064801.GA11635@parodius.com>

next in thread | previous in thread | raw e-mail | index | archive | help
>>>>> On Fri, 18 Apr 2003 23:48:01 -0700, 
>>>>> Jeremy Chadwick <freebsd@jdc.parodius.com> said:

>         The secondary is configured literally identical to the
>         primary, except that the IPs have changed and _all_ of
>         the zones are type slave.

>         I see the exact same problem on the secondary (again,
>         outgoing traffic on the public interface with an IP of
>         the private), except that the src & dst IPs apply to
>         the private IP on the secondary and the WAN IP of the
>         primary, respectively.  Sorry if that's confusing.  :-)

>         I believe removing the query-source option could in fact
>         solve the problem, but there is a specific reason for it's
>         existance -- we rely on the MAPS RBL+ service for SBL lookups,
>         which are DNS based.  Permission to the RBL+ service is based
>         on the IP doing the query.  Since the nameserver IPs are
>         IP aliases, if I do not specify this, the queries come from
>         the first IP in the list shown in ifconfig -a.

>         If there's a workaround for this, I'd love to hear it.  :-)

I guess the query from the client that caused the problem was the SOA
check before zone transfer.  If this is correct, you can control the
source address of such queries with BIND 9's transfer-source.  So,
please try:

1. install BIND 9 at the secondary server.
2. add the following in the zone statement for which the secondary
   serves:
   transfer-source 10.0.0.2;

I don't know the reason for the error at the secondary side.

					JINMEI, Tatuya
					Communication Platform Lab.
					Corporate R&D Center, Toshiba Corp.
					jinmei@isl.rdc.toshiba.co.jp



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?y7v4r4ucw46.wl>