PDA

View Full Version : DNS: dot querys



A13923
18-Sep-2012, 19:06
Today I have installed a nameserver using bind. After configuring the first clients I noticed a problem when logging of. Each logoff causes a delay from about 10 seconds.

I tried to identify the problem using tcpdump. And I could see that with each logoff and DNS query "." is running.


16:07:23.373217 IP fcbsrv03.36468 > fcbxen53.domain: 18357+ A? . (17)

So the first question is "what is the reason for the dot query"?

I checked a nameserver in an other environment and this server answers the query with a quick


pagdns001:/var/lib/named/master # nslookup .
Server: 172.23.0.8
Address: 172.23.0.8#53

Non-authoritative answer:
*** Can't find .: No answer

But the new nameserver is forwarding the query to his forwarders and ends with a timeout after 10 to 15 seconds. Which is causing the delay when logging off.


fcbsrv03:~ # time nslookup .
;; connection timed out; no servers could be reached


real 0m15.026s
user 0m0.008s
sys 0m0.004s

I have double-checked the configuration but I could not find a difference. So why does the new server forward the request and the other one not?

Automatic reply
27-Sep-2012, 13:30
A13923,

It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.

Has your issue been resolved? If not, you might try one of the following options:

- Visit http://www.suse.com/support and search the knowledgebase and/or check all
the other support options available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.suse.com)

Be sure to read the forum FAQ about what to expect in the way of responses:
http://forums.suse.com/faq.php

If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.

Good luck!

Your SUSE Forums Team
http://forums.suse.com

summitflier
01-Apr-2013, 19:11
Have you created a root hints file for your DNS server?
Is this a real registered domain with a real SOA? ( or just a local internal domain? )

what does your nsswitch.conf and resolv.conf look like on the one that doesn't work?

jmozdzen
03-Apr-2013, 13:17
Hi A13923,

> Today I have installed a nameserver using bind. [...] I tried to identify the problem using tcpdump.

what type of server did you set up - a simple forwarder, or does this DNS server answer local zones, too?
Did you try turning query logging on within the DNS server?

That "." query does seem a bit strange, indeed. How's the "." zone set up in your named.conf? Is is somehow included in other configuration elements (included files, LDAP, ...)? Do "." zone dumps from both name daemons compare?

Maybe I should have asked first... *what* named daemon have you set up, and on which platform? ;)

Regards,
Jens