D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] intermittant resolver issues

 

Simon - so far so good - ditched the forwarders and, as the fact I can send this message proves, can at least connect - well at least for now anyway!!.

Non cached name resolution seems to be VERY VERY slow however - like up to 10/15 secs (ish) for some sites.

Still cannot understand what has altered to cause the problem after all this time trouble free nor why name resolution is now so desperately bad although have yet to stick tracing on to try to pin it down.

Due to the intermittent nature of the original problem, I cannot yet say for sure this is a complete fix - will keep y'all posted.

Thanks for the help

David


----- Original Message ----- From: "Simon Waters" <simon@xxxxxxxxxxxxxx>

David Brook wrote:

We do have forwarders listed in our DNS config file pointing at the BT
DNS servers. I thought this was the only way to chain DNS queries from
our domain to the outside world. It has always worked in the past!!!! .

Forwarders are evil.

If you run your own DNS server for recursive queries, it should resolve
off the root name servers (don't worry there are a lot more than 13 of
them in reality).

These days best to avoid forwarders unless your expensive DNS consultant
says otherwise.

I'd lose the forwarder, and see if the problems go away first. Do check
your firewall config allows outgoing DNS queries to port 53 both UDP and
TCP to any address from your DNS server.

Also once the forwarders are gone you can expect BIND to do roughly the
same as "dig +trace www.example.com", which helps no end in troubleshooting.




-
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe. FAQ: www.dcglug.org.uk/linux_adm/list-faq.html