Solved

Forward not working in Bind

Posted on 2009-06-30
5
1,403 Views
Last Modified: 2013-12-23
We are not able to forward requeses to the servers listed:

zone "xxx.com" IN {
       type forward;
       forwarders { xxx.xxx.104.13; xxx.xxx.104.40; };
};
0
Comment
Question by:axl13
  • 3
  • 2
5 Comments
 
LVL 4

Expert Comment

by:Adraenyse
ID: 24747679
Can you post the Options portion of your configuration, and what leads you to believe that it is not working?
0
 

Author Comment

by:axl13
ID: 24747711
options {
#
        directory       "/var/named";
        pid-file        "/var/named/named.pid";
        allow-transfer { xxx.xxx/16; };
        transfer-format one-answer;
        };
logging {
        channel my_file {
                file "/var/named/dns.log";
                severity dynamic;
                print-category yes;
                print-severity yes;
                print-time yes;
                };
#       category default { my_file; };
        category update { my_file; };
        category notify { my_file; };
        category xfer-in { my_file; };
        category xfer-out { my_file; };
#       category security { my_file; };
#       category queries { my_file; };
        };

nslookup turns up server cant find domain: Non-existent domain
0
 

Author Comment

by:axl13
ID: 24868971
Still not able to get FORWARD to work...
0
 
LVL 4

Expert Comment

by:Adraenyse
ID: 24869656
You have no forwarders in your options. Do you have a root hints zone? If not, there is no where for bind to look up any information.


In your options section you need a forwarders statement such as:

forwarders      { 208.67.222.222; 208.67.220.220; };

(These are the OpenDNS servers. I prefer them over any of my ISP servers as they are more reliable and answer faster. http://www.opendns.com/)
Not directly related to your question, but I would recommend also having an allow-recursion statement in your options section for your local subnets or bind will not fully resolve queries for your local machines.

allow-recursion { 127.0.0.1; xx.xx.xx.xx/16; };

Using the statement forward first in the options section will tell bind to try your forwarders first, and if unsucessful, then proceed to query the root zone servers for an answer.

forward first;

If you do not have a root hints zone, this is how you create one

- Connect to ftp.internic.net as anonymous and download domain/named.root- Place named.root in your /var/named directory and chown it named.named and chmod it to 444
- Add the following zone statement to named.conf (outside of the options statement of course)

zone "." { type hint; file "named.root"; };

Hope that helps
Adrae
0
 

Accepted Solution

by:
axl13 earned 0 total points
ID: 25854028
We could not get the forwarding to work, so we had the users seconday the zone
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VLAN CONFIGURATION 2 58
TLS 1.0 & Windows 7 - How to disable? 16 119
Exchange 2016 - not receiving mail 17 43
Outlook PST (cloud) backup 3 16
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question