[rbldnsd] How to implement?

Chris Knipe savage at savage.za.org
Thu Aug 11 18:35:19 MSD 2005


Perhaps I spoke to soon... This is what I don't quite get and understand...

root at playtopus:~# dig +trace 253.64.241.200.ma.dnsbl.cenergynetworks.com

; <<>> DiG 9.3.1 <<>> +trace 253.64.241.200.ma.dnsbl.cenergynetworks.com
;; global options:  printcmd
..                       505440  IN      NS      F.ROOT-SERVERS.NET.
..                       505440  IN      NS      G.ROOT-SERVERS.NET.
..                       505440  IN      NS      H.ROOT-SERVERS.NET.
..                       505440  IN      NS      I.ROOT-SERVERS.NET.
..                       505440  IN      NS      J.ROOT-SERVERS.NET.
..                       505440  IN      NS      K.ROOT-SERVERS.NET.
..                       505440  IN      NS      L.ROOT-SERVERS.NET.
..                       505440  IN      NS      M.ROOT-SERVERS.NET.
..                       505440  IN      NS      A.ROOT-SERVERS.NET.
..                       505440  IN      NS      B.ROOT-SERVERS.NET.
..                       505440  IN      NS      C.ROOT-SERVERS.NET.
..                       505440  IN      NS      D.ROOT-SERVERS.NET.
..                       505440  IN      NS      E.ROOT-SERVERS.NET.
;; Received 244 bytes from 63.246.155.12#53(63.246.155.12) in 10 ms

com.                    172800  IN      NS      H.GTLD-SERVERS.NET.
com.                    172800  IN      NS      I.GTLD-SERVERS.NET.
com.                    172800  IN      NS      J.GTLD-SERVERS.NET.
com.                    172800  IN      NS      K.GTLD-SERVERS.NET.
com.                    172800  IN      NS      L.GTLD-SERVERS.NET.
com.                    172800  IN      NS      M.GTLD-SERVERS.NET.
com.                    172800  IN      NS      A.GTLD-SERVERS.NET.
com.                    172800  IN      NS      B.GTLD-SERVERS.NET.
com.                    172800  IN      NS      C.GTLD-SERVERS.NET.
com.                    172800  IN      NS      D.GTLD-SERVERS.NET.
com.                    172800  IN      NS      E.GTLD-SERVERS.NET.
com.                    172800  IN      NS      F.GTLD-SERVERS.NET.
com.                    172800  IN      NS      G.GTLD-SERVERS.NET.
;; Received 501 bytes from 192.5.5.241#53(F.ROOT-SERVERS.NET) in 70 ms

cenergynetworks.com.    172800  IN      NS      ns1.cenergynetworks.com.
cenergynetworks.com.    172800  IN      NS      ns2.cenergynetworks.com.
cenergynetworks.com.    172800  IN      NS      ns3.cenergynetworks.com.
cenergynetworks.com.    172800  IN      NS      ns4.cenergynetworks.com.
;; Received 197 bytes from 192.54.112.30#53(H.GTLD-SERVERS.NET) in 109 ms

dnsbl.cenergynetworks.com. 86400 IN     NS      ns5.cenergynetworks.com.
;; Received 95 bytes from 196.30.191.122#53(ns1.cenergynetworks.com) in 234 
ms

dnsbl.cenergynetworks.com. 3600 IN      SOA     dnsbl.cenergynetworks.com. 
rbl.cenergynetworks.com. 1123755462 7200 7200 604800 3600
;; Received 101 bytes from 196.30.191.123#53(ns5.cenergynetworks.com) in 
1296 ms

Up to there, everything seems to be fine.  The record does not exist... 
HOWEVER...

root at playtopus:~# nslookup 253.64.241.200.ma.dnsbl.cenergynetworks.com
Server:         63.246.155.12
Address:        63.246.155.12#53

** server can't find 253.64.241.200.ma.dnsbl.cenergynetworks.com: SERVFAIL

Now, I get a server failure?

Restarting the named deamon, and running the query again, nslookup returns a 
NXDOMAIN.    After running for a couple of hours, SERVFAIL.


Thanks,
Chris.





----- Original Message ----- 
From: "Chris Knipe" <savage at savage.za.org>
To: "Small Daemon for DNSBLs" <rbldnsd at corpit.ru>
Sent: Thursday, August 11, 2005 2:34 PM
Subject: Re: [rbldnsd] How to implement?


>>> I need to get rbldnsd running again, but I must have ACLs on it to limit
>>> who can submit queries to it....
>>
>> Hmm.  Can you perhaps try new 'acl' "dataset" in recent rbldnsd?
>>
>
> I wasn't even aware of that :) Thanks, will check it out.
>
> The problem was some negative cache somewhere.  Restarted bind on the 
> machines giving problems, and it all started to work again magically. 
> Perhaps I just made to many changes to quickly in a attempt to try and 
> resolve my problem.
>
> Thanks for your input :)
>
> --
> Chris.
>
>
> _______________________________________________
> rbldnsd mailing list
> rbldnsd at corpit.ru
> http://www.corpit.ru/mailman/listinfo/rbldnsd
> 




More information about the rbldnsd mailing list