Issue with Bind9 forwarding


Recommended Posts

Hi All,

I have an odd problem with Bind - which is driving me a little insane, and I cannot for the life of me find the cause.

I have bind setup on a box in my network to handle internal DNS. This is setup as a forwarder to a couple of other servers. All works fine. Randomly however, Bind will stop logging and stop forwarding requests. Requests that bind has zones for work fine, however it will refuse to forward any request to any of the 3 servers its set to forward to. There's also nothing in the log - once this starts happening, bind stops writing to the log.

I've tried changing the forwarders, and reinstalling bind - but it still does the same thing. Sometimes it lasts a day, sometimes it lasts a month, and restarting bind always fixes it. Any ideas what might be causing it?

(PS I should add that this DNS server is behind my firewall, so its not publicly accessible).

Link to comment
Share on other sites

Nope there's no domain controller (it's just my local network - no need for anything like that).

It's just a Debian box which has the usual LAMP stuff, mysql, netatalk and samba, etc (just the normal network stuff).

Link to comment
Share on other sites

What version of bind 9.x? running on what version of debian and what is the config?  Is this a physical box or a virtual box where you run bind.

Link to comment
Share on other sites

It's a physical box. It has a static IP, and is set to use itself (plus a backup) for its own DNS lookups.

It's running Debian 7.4, and bind 9.8.4:

BIND 9.8.4-rpz2+rl005.12-P1 built with '--prefix=/usr' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--sysconfdir=/etc/bind' '--localstatedir=/var' '--enable-threads' '--enable-largefile' '--with-libtool' '--enable-shared' '--enable-static' '--with-openssl=/usr' '--with-gssapi=/usr' '--with-gnu-ld' '--with-geoip=/usr' '--enable-ipv6' 'CFLAGS=-fno-strict-aliasing -DDIG_SIGCHASE -O2'

using OpenSSL version: OpenSSL 1.0.1e 11 Feb 2013

using libxml2 version: 2.8.0

It's just setup as a standard DNS server with a zone for the domain I use here, forwarding enabled with 3 servers to forward to, and lookups limited to my IP range here. Again, it's not externally accessible (it's behind a hardware firewall).

Link to comment
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.