Master-Master-Slave BIND setup

We have a primary DNS server in the network but for some reason (likely due to security changes) it sometimes fails to respond DNS updates to the BIND slaves.

Is it possible to have a tiered slave system so if an urgent DNS record update is required when the primary server is partially unresponsive it steps down?

I.E.
Master > Slave 1 > Slave 2

So Slave 2 would get DNS updates from Slave 1 rather than Master?

That way if need be we can turn a zone from slave to master instantly on Slave 1 and Slave 2 would get the updates for our zones until we sort out the issues on Master then we can simply return the affected zone on Slave 1 back to a Slave zone>
LVL 6
kiwistagAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

arnoldCommented:
First remedy is to make sure your soa/ttl settings are such that provide you sufficient time to correct the issue.
Master => slaves
You could convert one of the slave DNS servers to be the new master while updating the remaining slave to reflect the new master.

Your question lacks detail chaining

The way bind works when you have notify settings relied on based on the NS records in the zone when a zone is updated on the master a notification is sent to NS record servers. The serial number of the zone if not changed, will lead to the change not propagating.
If NS servers are not referenced, your named.conf shoukd include the option also-notify {ipaddress_slave1;ipaddress_slave2};
The DNS servers need transfer rights on zones from master.....

DNS port 53 udp/TCP

On a slave
Dig @master axfr donain.com.
See what you get..

Often the issue with a change taking a long time or until a reboot/restart of named is forgetting to update the serial or not the change not increasing the serial compared ..
Run
host -C domainname.com

It should list the serial number for the zone on each listed name server.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
kiwistagAuthor Commented:
Reverted just keeping one master server since we also use DKIM.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
DNS

From novice to tech pro — start learning today.