# Rfc2136 / bind 9 RFC2136 update failed: bad return code: NOTZONE"

**URL:** <https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521>\
**Category:** SUSE Rancher Prime\
**Created:** [May 22, 2020, 8:55am UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521 "2020-05-22T08:55:30Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rprengel](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@rprengel](https://forums.suse.com/u/rprengel)\
**Post date:** [May 22, 2020, 8:55am UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/1 "2020-05-22T08:55:30Z")

</div>

Hallo,  
next round to user rfc2136 with an bind 9.  
Connection is working now but RFC2136 update failed: bad return code: NOTZONE appears.  
has anyone an idea wthat is going wrong?  
I used this tutorial.

> **[How To Configure BIND as a Private Network DNS Server on CentOS 7 | DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-configure-bind-as-a-private-network-dns-server-on-centos-7)**
>
> In this tutorial, we will go over how to set up an internal DNS server, using the BIND name server software (BIND9) on CentOS 7, that can be used by your Virtual Private Servers (VPS) to resolve private host names and private IP addresses. This...

  
I m using external-dns Version 3.0.2 fom the bitnami catalog.

Thanks for hints  
Ralf

time=“2020-05-22T08:47:48Z” level=info msg=“Adding RR: [srvrancherprod.comline.de](http://srvrancherprod.comline.de) 0 A 192.168.242.160”

time=“2020-05-22T08:47:48Z” level=info msg=“Adding RR: [srvrancherprod.comline.de](http://srvrancherprod.comline.de) 0 A 192.168.243.28”

time=“2020-05-22T08:47:48Z” level=info msg=“Adding RR: [srvrancherprod.comline.de](http://srvrancherprod.comline.de) 0 A 192.168.245.100”

time=“2020-05-22T08:47:48Z” level=info msg="Adding RR: [srvrancherprod.comline.de](http://srvrancherprod.comline.de) 0 TXT “heritage=external-dns,external-dns/owner=default,external-dns/resource=ingress/default/webseite01"”

time=“2020-05-22T08:47:48Z” level=info msg=“Bad dns.Client.Exchange response: ;; opcode: UPDATE, status: NOTZONE, id: 7685\n;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1\n\n;; QUESTION SECTION:\n;docker.comline.local.\tIN\t SOA\n\n;; ADDITIONAL SECTION:\n\n;; TSIG PSEUDOSECTION:\nrndc-key.\t0\tCLASS255\tTSIG\t hmac-md5.sig-alg.reg.int. 20200522084747 300 16 400F568B6370E567C109E41F0443C694 7685 0 0 \n”

time=“2020-05-22T08:47:48Z” level=error msg=“RFC2136 update failed: bad return code: NOTZONE”

Here my zoen files

$TTL 604800  
@ IN SOA srvbind92.docker.comline.locale. admin.docker.comline.local. (  
3 ; Serial  
604800 ; Refresh  
86400 ; Retry  
2419200 ; Expire  
604800 ) ; Negative Cache TTL  
;  
; name servers - NS records  
IN NS srvbind92.docker.comline.local.  
IN NS 000c29ddec8c.docker.comline.local.

; name servers - A records  
srvbind92.docker.comline.local. IN A 192.168.241.85  
000c29ddec8c.docker.comline.local. IN A 192.168.242.253

$TTL 604800  
@ IN SOA srvbind92.docker.comline.local. admin@docker.comline.local. (  
3 ; Serial  
604800 ; Refresh  
86400 ; Retry  
2419200 ; Expire  
604800 ) ; Negative Cache TTL  
; name servers - NS records  
IN NS srvbind92.docker.comline.local.  
IN NS 000c29ddec8c.docker.comline.local.

; PTR Records  
85.241 IN PTR srvbind92.docker.comline.local. ;192.168.241.85  
253.242 IN PTR 000c29ddec8c.docker.comline.local. ;192.168.242.253

---

<div class="post-metadata">

**Author:** ![rprengel](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@rprengel](https://forums.suse.com/u/rprengel)\
**Post date:** [May 22, 2020, 11:34am UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/2 "2020-05-22T11:34:59Z")

</div>

solved:  
domain Rancher is named [firma.de](http://firma.de) , dns zone in my bind is firma.local.  
rfc2136 is configure to use firma.local.  
Reconfiguring my dns zone in bind in [firma.de](http://firma.de) solved the problem for the moment as a first test.  
Question ist how to reconfigure rancher info firma.local.

Ralf

---

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [May 22, 2020, 11:30pm UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/3 "2020-05-22T23:30:07Z")

</div>

Hi Ralf,

Just to clarify, this is in regards to external DNS outside the cluster, correct? You are not trying to use rtc2136 inside the cluster (Core DNS does that in Rancher 2).

The `rfc2136.zone` option will set the zone used in the records.

Check out the RFC 2136 tutorial at [https://github.com/kubernetes-sigs/external-dns/blob/master/docs/tutorials/rfc2136.md](https://github.com/kubernetes-sigs/external-dns/blob/master/docs/tutorials/rfc2136.md) and see if that helps you. It took me several tries. The `--dry-run` and `--log-level=debug` options helped a lot.

Note that the Bitnami chart will accept options even if they are invalid, so watch out for typos. You can doublecheck the options by inspecting the Kubernetes YAML. An invalid option will NOT be passed onto Kubernetes and therefore will not appear under `spec.containers.args` if you check it:

```
docker01 $ kubectl get deploy external-dns -n external-dns -o yaml
...
    spec:
      containers:
      - args:
        - --log-level=info
        - --log-format=text
        - --domain-filter=rancher.example.org
        - --rfc2136-zone=rancher.example.org.
...
```

---

<div class="post-metadata">

**Author:** ![rprengel](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@rprengel](https://forums.suse.com/u/rprengel)\
**Post date:** [May 23, 2020, 4:54am UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/4 "2020-05-23T04:54:23Z")

</div>

Hallo,  
yes that is correct. The bind9 is a vmware system running in the network.  
I can see in the logfile of the rfc2136 container that it uses as RR [name.company.de](http://name.company.de). Is there a way to change it in name.company.local?  
A second question.  
In our rancher 1.6 environement the rfc2136 container has the option ro define the sended dns name using some variables. Is there an similar option existing for external dns?  
Thanks  
Ralf

---

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [May 26, 2020, 8:54pm UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/5 "2020-05-26T20:54:50Z")

</div>

> [@rprengel](#):
>
> In our rancher 1.6 environement the rfc2136 container has the option ro define the sended dns name using some variables. Is there an similar option existing for external dns?

Yes, this is called the [FQDN Template](https://github.com/kubernetes-sigs/external-dns/blob/d25d6480300e1160b6892335105e5fd4fb62d8d3/docs/faq.md#how-do-i-specify-a-dns-name-for-my-kubernetes-objects), which should support options such as `--fqdn-template "{.metadata.name}.{metadata.namespace}"`.

Personally, I have not gotten this to work with Rancher yet, because Rancher’s web form for the ingress requires that a human set up some sort of name.

---

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [May 26, 2020, 8:56pm UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/6 "2020-05-26T20:56:54Z")

</div>

> [@rprengel](#):
>
> yes that is correct. The bind9 is a vmware system running in the network.  
> I can see in the logfile of the rfc2136 container that it uses as RR [name.company.de](http://name.company.de). Is there a way to change it in name.company.local?

Can you post your external-dns configuration, minus any sensitive data like the TSIG keys?

---

<div class="post-metadata">

**Author:** ![rprengel](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@rprengel](https://forums.suse.com/u/rprengel)\
**Post date:** [May 27, 2020, 4:42am UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/7 "2020-05-27T04:42:18Z")

</div>

Hallo,  
I will do this later this week.  
Thanks for your help.  
Ralf

---

<div class="post-metadata">

**Author:** ![rprengel](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@rprengel](https://forums.suse.com/u/rprengel)\
**Post date:** [May 28, 2020, 9:45am UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/8 "2020-05-28T09:45:42Z")

</div>

Hallo,  
I ve a simple working config for the moment.  
Because of corona everything about Rancher 2.4 is on stand-by now.  
For the next time will bring only systems up that are working out of box and dns is really tricky with rancher 2.4.  
The things we need for the moment for our developers are working using Ingress.

Ralf

---

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [May 28, 2020, 5:21pm UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/9 "2020-05-28T17:21:41Z")

</div>

I agree that External DNS is pretty tricky with Rancher 2. Rancher 2 has DNS integrations for cloud providers, but we need solutions that work on-premise.

I’m also just a Rancher 2 end user. It took me a while to get the External DNS RFC2136 provider working as needed with Rancher 2. I had to find a happy medium that worked with External DNS, Nginx Ingress, and the Rancher 2 UI.

My next step is to try and figure out how to use [FQDN Templates](https://github.com/kubernetes-sigs/external-dns/blob/d25d6480300e1160b6892335105e5fd4fb62d8d3/docs/faq.md#how-do-i-specify-a-dns-name-for-my-kubernetes-objects) to simplify what our users need to do. Currently, Rancher 2 requires users to type in a hostname, but external-dns can do this programmatically— I’m unsure how to bridge the two worlds.

Feel free to join us in the k8s Slack channel #external-dns.

-= Stefan

---

<div class="post-metadata">

**Author:** ![rprengel](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@rprengel](https://forums.suse.com/u/rprengel)\
**Post date:** [June 2, 2020, 6:54am UTC](https://forums.suse.com/t/rfc2136-bind-9-rfc2136-update-failed-bad-return-code-notzone/17521/10 "2020-06-02T06:54:55Z")

</div>

Hallo,  
can you post an example of your config for the template to rewrite the dns entry?  
Thanks  
Ralf
