Re: resolver doesn't see resolv.conf changes



Ulrich Spoerlein wrote:
Lyndon Nerenberg wrote:
The solution is to run a local caching nameserver instance. You should do this anyway, for performance reasons. Add 'named_enable="YES"' to /etc/rc.conf, and modify your /etc/dhclient.conf as follows:

Good idea, but this defeates the hierarchical purpose of DNS. Now my
caching DNS is always querying the root DNS servers.

Yes, and is actually sending valid queries driven by a human trying to do something useful. Serving legitimate traffic isn't a problem for the root nameservers, but you could always set up a forwarder line to use the local ISP's nameserver first.

[ The root nameservers are seeing upwards of 90% bogus queries (ie, invalid queries, misplaced assertions from DNS servers claiming to be root nameservers themselves, Kaspersky-style DoS attacks, etc). ]

And there might be ISPs who disallow outgoing DNS connections to
somewhere else than their own DNS servers.

There are people offering "walled gardens" which prevent normal Internet access but provide some limited services; such aren't really "ISP"s, though.

--
-Chuck

_______________________________________________
freebsd-stable@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-stable
To unsubscribe, send any mail to "freebsd-stable-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Question re: DNS forwarding best practices
    ... > Lets say you have a company with a root AD domain, ... > in all domains are DNS servers, ... while the child domains have DC's spread across ... Correct it won't work for the Win2k boxes ...
    (microsoft.public.windows.server.dns)
  • Re: GC Question
    ... the toplevel Domain Root Dns Servers are always available, ... accounts what tool should I use to make sure that i'm not using a user ... Why some Dns folders are only available on the top root Domain? ... other domains in the forest don't have Several folders that the top root ...
    (microsoft.public.win2000.active_directory)
  • Re: DNS Server Recursive Name Resolution
    ... My main office is the forest root and has 2 DC's with DNS on each. ... On both DNS servers i have forwarding set to my ... Child Domain DCs/DNS servers to forward to NON Root DNS for Recursive Name ...
    (microsoft.public.windows.server.dns)
  • Re: Restore DC -need your advice. Urgent!
    ... - Try to restore from backup. ... and try to perform a DB repair an/or clean the log files and .chk file. ... We have two root domain controllers which handle our external DNS (no users ... which forward to the external DNS servers after child DC DNS servers forward ...
    (microsoft.public.windows.server.active_directory)
  • Re: Unable to create an additional DC using dcpromo at remote site
    ... You are using single-label domain name for your root domain. ... SP4 + need additional configuration for working with single-label domain ... The proposed Dc at the remote site is currently in the W2k3 domain. ... The DNS servers used by this computer for name resolution are not ...
    (microsoft.public.windows.server.active_directory)