PDA

View Full Version : DNS ouestion


doncro
21st November 2006, 19:14
First ,Thanks for ISPconfig It's great!

I set up DNS servers with Falcos how to set up ans with ispconfig and godaddy with theese exceptions.
I used zoneedit for the dns servers for:
ns1.akitaserver.com
ns3.akitaserver.com
Both akitaserver.com and akitamag.com are registered with ACT NOW whitch is a godaddy reseller I think
all test apear to be ok.
Act now gives error dtected when I try to change nameservers of akitamag.com to ns1.akitaserver.com 208.17.66.16 and
ns3.akitaserver.com 208.17.66.17
master nameserver log:

Nov 21 10:08:17 server1 named[6711]: shutting down: flushing changes
Nov 21 10:08:17 server1 named[6711]: stopping command channel on 127.0.0.1#953
Nov 21 10:08:17 server1 named[6711]: stopping command channel on ::1#953
Nov 21 10:08:17 server1 named[6711]: no longer listening on 127.0.0.1#53
Nov 21 10:08:17 server1 named[6711]: no longer listening on 208.17.66.16#53
Nov 21 10:08:17 server1 named[6711]: exiting
Nov 21 10:08:17 server1 named[8697]: starting BIND 9.3.1 -t /var/lib/named -u
named
Nov 21 10:08:17 server1 named[8697]: found 1 CPU, using 1 worker thread
Nov 21 10:08:17 server1 named[8697]: loading configuration from
'/etc/named.conf'
Nov 21 10:08:17 server1 named[8697]: listening on IPv4 interface lo,
127.0.0.1#53
Nov 21 10:08:17 server1 named[8697]: listening on IPv4 interface eth0,
208.17.66.16#53
Nov 21 10:08:17 server1 named[8697]: command channel listening on
127.0.0.1#953
Nov 21 10:08:17 server1 named[8697]: command channel listening on ::1#953
Nov 21 10:08:17 server1 named[8697]: zone 0.0.127.in-addr.arpa/IN: loaded
serial 42
Nov 21 10:08:17 server1 named[8697]: zone 66.17.208.in-addr.arpa/IN: loaded
serial 2006111903
Nov 21 10:08:17 server1 named[8697]: zone akitamag.com/IN: loaded serial
2006111904
Nov 21 10:08:17 server1 named[8697]: running
Nov 21 10:08:17 server1 named[8697]: zone 66.17.208.in-addr.arpa/IN: sending
notifies (serial 2006111903)
Nov 21 10:08:17 server1 named[8697]: zone akitamag.com/IN: sending notifies
(serial 2006111904)
Nov 21 10:09:07 server1 nmbd[7425]: [2006/11/21 10:09:07, 0]
nmbd/nmbd_become_lmb.c:become_local_master_stage2(396)
Nov 21 10:09:07 server1 nmbd[7425]: *****
Nov 21 10:09:07 server1 nmbd[7425]:
Nov 21 10:09:07 server1 nmbd[7425]: Samba name server SERVER1 is now a local
master browser for workgroup AKITA-ROOM on subnet 208.17.66.16
Nov 21 10:09:07 server1 nmbd[7425]:
Nov 21 10:09:07 server1 nmbd[7425]: *****
Nov 21 10:30:01 server1 /usr/sbin/cron[9068]: (root) CMD
(/root/ispconfig/php/php /root/ispconfig/scripts/shell/check_services.php
&> /dev/null)

Slave DNS server log:

Nov 21 10:08:17 server1 named[6711]: shutting down: flushing changes
Nov 21 10:08:17 server1 named[6711]: stopping command channel on 127.0.0.1#953
Nov 21 10:08:17 server1 named[6711]: stopping command channel on ::1#953
Nov 21 10:08:17 server1 named[6711]: no longer listening on 127.0.0.1#53
Nov 21 10:08:17 server1 named[6711]: no longer listening on 208.17.66.16#53
Nov 21 10:08:17 server1 named[6711]: exiting
Nov 21 10:08:17 server1 named[8697]: starting BIND 9.3.1 -t /var/lib/named -u
named
Nov 21 10:08:17 server1 named[8697]: found 1 CPU, using 1 worker thread
Nov 21 10:08:17 server1 named[8697]: loading configuration from
'/etc/named.conf'
Nov 21 10:08:17 server1 named[8697]: listening on IPv4 interface lo,
127.0.0.1#53
Nov 21 10:08:17 server1 named[8697]: listening on IPv4 interface eth0,
208.17.66.16#53
Nov 21 10:08:17 server1 named[8697]: command channel listening on
127.0.0.1#953
Nov 21 10:08:17 server1 named[8697]: command channel listening on ::1#953
Nov 21 10:08:17 server1 named[8697]: zone 0.0.127.in-addr.arpa/IN: loaded
serial 42
Nov 21 10:08:17 server1 named[8697]: zone 66.17.208.in-addr.arpa/IN: loaded
serial 2006111903
Nov 21 10:08:17 server1 named[8697]: zone akitamag.com/IN: loaded serial
2006111904
Nov 21 10:08:17 server1 named[8697]: running
Nov 21 10:08:17 server1 named[8697]: zone 66.17.208.in-addr.arpa/IN: sending
notifies (serial 2006111903)
Nov 21 10:08:17 server1 named[8697]: zone akitamag.com/IN: sending notifies
(serial 2006111904)
Nov 21 10:09:07 server1 nmbd[7425]: [2006/11/21 10:09:07, 0]
nmbd/nmbd_become_lmb.c:become_local_master_stage2(396)
Nov 21 10:09:07 server1 nmbd[7425]: *****
Nov 21 10:09:07 server1 nmbd[7425]:
Nov 21 10:09:07 server1 nmbd[7425]: Samba name server SERVER1 is now a local
master browser for workgroup AKITA-ROOM on subnet 208.17.66.16
Nov 21 10:09:07 server1 nmbd[7425]:
Nov 21 10:09:07 server1 nmbd[7425]: *****
Nov 21 10:30:01 server1 /usr/sbin/cron[9068]: (root) CMD
(/root/ispconfig/php/php /root/ispconfig/scripts/shell/check_services.php
&> /dev/null)

any suggestions about the problem?
Thanks in advance.
Don

falko
22nd November 2006, 17:34
I don't see any errors in your logs, but the nameservers for akitamag.com are park25 and park26.secureserver.net:

mh1:~# dig ns akitamag.com

; <<>> DiG 9.2.1 <<>> ns akitamag.com
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 57280
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;akitamag.com. IN NS

;; ANSWER SECTION:
akitamag.com. 3596 IN NS PARK26.SECURESERVER.NET.
akitamag.com. 3596 IN NS PARK25.SECURESERVER.NET.

;; Query time: 2 msec
;; SERVER: 81.169.163.104#53(81.169.163.104)
;; WHEN: Wed Nov 22 16:32:34 2006
;; MSG SIZE rcvd: 88What's the exact error message you got from ACT?

doncro
22nd November 2006, 17:52
Thanks for the reply Falco.
I only get the Errors detected msg!
I have waited 48 hours to try and change the akitamag.com
Don

doncro
22nd November 2006, 18:35
Sory Falco I checked my slave logs again. I must have sent you a copy of the master log twice . I do have a problem with notify. the slave server is behind a router with gateway 192.168.150 will I have to run the slave outside the router or is there a fix for the notify?

Log for server 3 slave

ov 22 10:18:06 server3 saslauthd[12574]: main : no authentication
mechanism specified
Nov 22 10:18:07 server3 syslog-ng[3268]: STATS: dropped 0
Nov 22 11:21:16 server3 named[26413]: shutting down: flushing changes
Nov 22 11:21:16 server3 named[26413]: stopping command channel on
127.0.0.1#953
Nov 22 11:21:16 server3 syslog-ng[3268]: STATS: dropped 0
Nov 22 11:21:16 server3 named[26413]: stopping command channel on ::1#953
Nov 22 11:21:16 server3 named[26413]: no longer listening on 127.0.0.1#53
Nov 22 11:21:16 server3 named[26413]: no longer listening on 192.168.1.110#53
Nov 22 11:21:16 server3 named[26413]: no longer listening on 192.168.1.111#53
Nov 22 11:21:16 server3 named[26413]: exiting
Nov 22 11:21:34 server3 named[13455]: starting BIND 9.3.1 -t /var/lib/named -u
named
Nov 22 11:21:34 server3 named[13455]: found 1 CPU, using 1 worker thread
Nov 22 11:21:34 server3 named[13455]: loading configuration from
'/etc/named.conf'
Nov 22 11:21:34 server3 named[13455]: listening on IPv4 interface lo,
127.0.0.1#53
Nov 22 11:21:34 server3 named[13455]: listening on IPv4 interface eth0,
192.168.1.110#53
Nov 22 11:21:34 server3 named[13455]: listening on IPv4 interface eth0:0,
192.168.1.111#53
Nov 22 11:21:34 server3 named[13455]: command channel listening on
127.0.0.1#953
Nov 22 11:21:34 server3 named[13455]: command channel listening on ::1#953
Nov 22 11:21:34 server3 named[13455]: zone 0.0.127.in-addr.arpa/IN: loaded
serial 42
Nov 22 11:21:34 server3 named[13455]: zone 1.168.192.in-addr.arpa/IN: loaded
serial 2006111901
Nov 22 11:21:34 server3 named[13455]: zone akitamag.com/IN: loaded serial
2006111904
Nov 22 11:21:34 server3 named[13455]: running
Nov 22 11:21:34 server3 named[13455]: zone 1.168.192.in-addr.arpa/IN: sending
notifies (serial 2006111901)
Nov 22 11:21:34 server3 named[13455]: zone akitamag.com/IN: sending notifies
(serial 2006111904)
Nov 22 11:21:34 server3 named[13455]: client 192.168.1.150#1453: received
notify for zone '1.168.192.in-addr.arpa'
Nov 22 11:21:35 server3 named[13455]: client 192.168.1.150#1453: received
notify for zone 'akitamag.com'
Nov 22 11:21:35 server3 named[13455]: zone akitamag.com/IN: refused notify
from non-master: 192.168.1.150#1453

thanks
Don

falko
23rd November 2006, 17:50
What's in pri.akitamag.com on the master and sec.akitamag.com on the slave?

doncro
23rd November 2006, 18:18
This is the master server pri.akitamag.com

$TTL 86400
@ IN SOA ns1.akitaserver.com. hostmaster.akitaserver.com. (
2006111904 ; serial, todays date + todays serial
#
28800 ; refresh, seconds
7200 ; retry, seconds
604800 ; expire, seconds
86400 ) ; minimum, seconds
;
NS ns1.akitaserver.com. ; Inet Address of
name server 1
NS ns3.akitaserver.com. ; Inet Address of
name server 2
;

MX 10 mail.akitamag.com.

akitamag.com. A 208.17.66.16
www A 208.17.66.16
mail A 208.17.66.16

;;;; MAKE MANUAL ENTRIES BELOW THIS LINE! ;;;;

This is the slave server sec.akitamag.com as you I have changed the slave from inside the router to outside aas well as the ip and still get the refuse notify but I think this is not a big problem as the slave has noone to notify.

$ORIGIN .
$TTL 86400 ; 1 day
akitamag.com IN SOA ns1.akitaserver.com. hostmaster.akitaserver.com. (
2006111904 ; serial
28800 ; refresh (8 hours)
7200 ; retry (2 hours)
604800 ; expire (1 week)
86400 ; minimum (1 day)
)
NS ns1.akitaserver.com.
NS ns3.akitaserver.com.
A 208.17.66.16
MX 10 mail.akitamag.com.
$ORIGIN akitamag.com.
mail A 208.17.66.16
www A 208.17.66.16

Thanks again
Don

falko
24th November 2006, 17:02
Both files contain the same information, so I think you should leave it as it is. You should check sec.akitamag.com after you have updated/added new records to pri.akitamag.com to see if the changes are also in sec.akitamag.com.

doncro
24th November 2006, 18:54
Ok Falco:
I modifyer records of akitamag with ispconfig. and got.
MASTER pri.akitamag
$TTL 86400
@ IN SOA ns1.akitaserver.com. hostmaster.akitaserver.com. (
2006112401 ; serial, todays date + todays serial
#
28800 ; refresh, seconds
7200 ; retry, seconds
604800 ; expire, seconds
86400 ) ; minimum, seconds
;
NS ns1.akitaserver.com. ; Inet Address of
name server 1
NS ns3.akitaserver.com. ; Inet Address of
name server 2
;

MX 10 mail.akitamag.com.

akitamag.com. A 208.17.66.16
www A 208.17.66.16

;;;; MAKE MANUAL ENTRIES BELOW THIS LINE! ;;;;

SLAVE sec.akitamag

$ORIGIN .
$TTL 86400 ; 1 day
akitamag.com IN SOA ns1.akitaserver.com. hostmaster.akitaserver.com. (
2006112401 ; serial
28800 ; refresh (8 hours)
7200 ; retry (2 hours)
604800 ; expire (1 week)
86400 ; minimum (1 day)
)
NS ns1.akitaserver.com.
NS ns3.akitaserver.com.
A 208.17.66.16
MX 10 mail.akitamag.com.
$ORIGIN akitamag.com.
www A 208.17.66.16

I am thinking there may be a problem on the other end with the akitamag regestry. I have mail addredd as hostmaster@akitaserver.com
which is sent to root maildir Is this ok?
Don

falko
25th November 2006, 15:27
Ok Falco:
I modifyer records of akitamag with ispconfig. and got.
MASTER pri.akitamag
$TTL 86400
@ IN SOA ns1.akitaserver.com. hostmaster.akitaserver.com. (
2006112401 ; serial, todays date + todays serial
#
28800 ; refresh, seconds
7200 ; retry, seconds
604800 ; expire, seconds
86400 ) ; minimum, seconds
;
NS ns1.akitaserver.com. ; Inet Address of
name server 1
NS ns3.akitaserver.com. ; Inet Address of
name server 2
;

MX 10 mail.akitamag.com.

akitamag.com. A 208.17.66.16
www A 208.17.66.16

;;;; MAKE MANUAL ENTRIES BELOW THIS LINE! ;;;;

SLAVE sec.akitamag

$ORIGIN .
$TTL 86400 ; 1 day
akitamag.com IN SOA ns1.akitaserver.com. hostmaster.akitaserver.com. (
2006112401 ; serial
28800 ; refresh (8 hours)
7200 ; retry (2 hours)
604800 ; expire (1 week)
86400 ; minimum (1 day)
)
NS ns1.akitaserver.com.
NS ns3.akitaserver.com.
A 208.17.66.16
MX 10 mail.akitamag.com.
$ORIGIN akitamag.com.
www A 208.17.66.16
sec.akitamag.com gets updated, so that's working and not the problem.

I have mail addredd as hostmaster@akitaserver.com
which is sent to root maildir Is this ok?
DonThat's also ok.

doncro
25th November 2006, 19:54
Should there be any reference to akitaserver.com or ns1 or ns3.akitaserver.com in the resolve.conf? There is not?
Don

falko
26th November 2006, 16:53
Should there be any reference to akitaserver.com or ns1 or ns3.akitaserver.com in the resolve.conf?
No. You only need at least one working nameserver there (IP address, not FQDN!).

doncro
27th November 2006, 08:58
The in-addr.arpa soa has a diffrent email address than the pri. SOA this is because the server is also postfix and the machine domain is akitasites.net
would this cause a problem? Also should this file be transfered to the slave?
Thanks
Don
<<>> DiG 9.3.1 <<>> @ns1.akitaserver.com 66.17.208.in-addr.arpa soa +norec
; (1 server found)
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39139
;; flags: qr aa ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 0

;; QUESTION SECTION:
;66.17.208.in-addr.arpa. IN SOA

;; ANSWER SECTION:
66.17.208.in-addr.arpa. 86400 IN SOA ns1.akitaserver.com.
hostmaster.akitasites.net. 2006112503 28800 7200 604800 86400

falko
28th November 2006, 16:01
That's no problem.

doncro
28th November 2006, 20:10
Falco
First I found that I did not need zoneedit to point to my nameservers at all ,but I did need to register or let Gododdy or secureserver know the nameservers existed.
The template has changed so much on godaddy and its resellers after
http://www.howtoforge.com/ispconfig_dns_godaddy that I have the process here.

Every thing is the same to this point. Then select and click on the domain to use as the nameserver.
screen1.jpg

On the next screen scroll to the bottom of the page on left. Choose ViewModify Detail
screen2.jpg

doncro
28th November 2006, 22:00
Next enter the ns1 and ip.address for that server and ns2 and ip.address for server
screen3.jpg

Return to the domains section and select the domain you have configured on master and slave server
Per http://www.howtoforge.com/ispconfig_dns_godaddy (http://www.howtoforge.com/ispconfig_dns_godaddy)Choose the domain you ad nameservers to
and click on the nameserver icon
screen4.jpg

list your nameservers under the custome nameservers tab.
screen5.jpg

After This I ran a test at http://www.dnsreport.com (http://www.dnsreport.com)and found I had open nameservers.
To correct this in /root/ispcinfig/isp/conf/named.conf.master I added “recursion no” to the options setion
Of each server. All checks ok now.
Thanks Falco for your help!
Don