?
Solved

Redhat 7.2 DNS server times out client requests, but appears to be running fine....

Posted on 2003-11-14
2
Medium Priority
?
516 Views
Last Modified: 2010-03-18
Using a Redhat 7.2 Linux box running bind 9.2.1 that I used to run a secondary DNS server on, but it is no longer responding to queries, although I see log file information recording that the queries were made.  I always get "connection timed out; no servers could be reached" or "DNS required timed out" on the client computer using either nslookup, dig, or host.  I'm trying queries from localhost, and a computer on the same network, so a firewall should not be an issue.

Any ideas what I am doing wrong?

Here is my /etc/resolve.conf

nameserver 0.0.0.0

Here is my /etc/named.conf

options {
        directory "/var/named";
        /*
         * If there is a firewall between you and nameservers you want
         * to talk to, you might need to uncomment the query-source
         * directive below.  Previous versions of BIND always asked
         * questions using port 53, but BIND 8.1 uses an unprivileged
         * port by default.
         */
        // query-source address * port 53;
};

//
// a caching only nameserver config
//
controls {
        inet 127.0.0.1 allow { localhost; } keys { rndckey; };
};

logging {
        channel namedlog {
                file "/var/log/named.log" versions 5 size 2m;
                print-time yes;
                print-category yes;
        };
        category "default" { namedlog; };
        category "general" { namedlog; };
        category "database" { namedlog; };
        category "security" { namedlog; };
        category "config" { namedlog; };
        category "resolver" { namedlog; };
        category "client" { namedlog; };
        category "unmatched" { namedlog; };
        category "queries" { namedlog; };
};

zone "." IN {
        type hint;
        file "named.ca";
};

zone "localhost" IN {
        type master;
        file "localhost.zone";
        allow-update { none; };
};

zone "0.0.127.in-addr.arpa" IN {
        type master;
        file "named.local";
        allow-update { none; };
};

zone "0.168.192.in-addr.arpa" IN {
        type master;
        file "named.0.168.192";
        allow-update { none; };
};

zone "200.113.216.in-addr.arpa" IN {
        type master;
        file "named.200.113.216";
        allow-update { none; };
};

include "/etc/rndc.key";
0
Comment
Question by:vancetech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 40

Accepted Solution

by:
jlevie earned 375 total points
ID: 9752447
If this DNS server is behind a firewall you need to uncomment the query -source directive in the options section.

And your resolv.conf on the DNS server should look like:

search mydomain.tld
nameserver 127.0.0.1

Your named.conf defines reverse zones, but it is missing a zone file for your domain. I presume from what named.conf contains that your reference to it being a "secondary DNS server" means that it is a caching server since neither of the local data zones (0.168.192.in-addr.arpa & 200.113.216.in-addr.arpa) are of type slave and you don't define any masters.
0
 

Author Comment

by:vancetech
ID: 9793324
jlevie,

Thanks for your response.  I had omitted the slave zones from the named.conf file above as there are a good number of them to fill up the screen.

My first problem was that zone transfers were not updating from the primary and I received "failure trying master: timed out" and "retry limit for master: exceeded" error messages in my log files.  Now, the server is unable to load the zones because they have all expired and are unable to contact the primary.

I'm going back to my original question, http://www.experts-exchange.com/Networking/Linux_Networking/Q_20795139.html
0

Featured Post

Enroll in August's Course of the Month

August's CompTIA IT Fundamentals course includes 19 hours of basic computer principle modules and prepares you for the certification exam. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses
Course of the Month9 days, 22 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question