Re: djbdns
- From: Stefaan A Eeckels <hoendech@xxxxxx>
- Date: Sat, 14 Oct 2006 16:27:10 +0200
On 14 Oct 2006 05:03:09 -0700
"Davide" <davide.papagno@xxxxxxxxx> wrote:
I love and used bind 8 when my dns was an authoritaive dns (it managed
almost 5000 domains!! without problem for more than 6 years).
Now my company moved 95% of all the domains in another country, so my
dns is now "just" a cache resolver with only 500 domains in it.
The result is that the CPU is costantly 90% used!!! with all the
problem it creates.. (latency in reply.. fake glue record and so on..)
Nothing changes on the sun box but the moving of about 4500 zones.
Do you mean that the change from server for 5000 domains to server for
500 domains caused an increase in CPU load? Somehow that sounds
strange, because if this box is acting as a DNS cache, your company's
4500 domains are but a drop in the ocean.
this dns is a real internet resolver (not an internal local area) so
it is used by millions of users every time.
So the problem is caused not by the disappearance of 4500 domains, but
the increase in use. BIND needs a lot of memory, and you don't mention
how much memory your Sun has. Given that the box is at least 6 years
old, it's safe to say that it doesn't have enough memory. A DNS cache
for millions of users needs at least 4GB but the more the merrier. And
it looks like you only have a single CPU - either upgrade the CPUs or
simply get a faster system. I think a T2000 with 32GB would make a very
nice DNS host.
So I really need a dns software who is smart in cache resolving and
authoritaive at the same time for the 500 zones remaining.
Unlucky I've got only one public IP so djbdns is not a valid solution.
Millions of users and only a single public IP address? Tell your
management to wake up and get you at least another machine, because
even with only 500 domains you need a primary and a secondary server.
Take care,
--
Stefaan A Eeckels
--
Effective cryptography is not about strong cryptographic algorithms.
It is instead about key management. -- Russell Nelson
.
- Follow-Ups:
- Re: djbdns
- From: Davide
- Re: djbdns
- References:
- djbdns
- From: Davide
- Re: djbdns
- From: Davide
- djbdns
- Prev by Date: Re: S10 disillusionment
- Next by Date: Re: apache-php5-mysql
- Previous by thread: Re: djbdns
- Next by thread: Re: djbdns
- Index(es):
Relevant Pages
|
Loading