i have adidcated server any i get anew one and my site is rock2host.com on the domain name i make the ns1 - ns2-ns3-ns4 of ips of the new server but the problem that to this time there is no any account on my server is working as i have adns error but i do not what is the problem i made that
DNS Functions Adding an A entry for your hostname Bind reloading on server using rndc zone: [rock2host.com] Error reloading bind on server: rndc: get config key list: not found
DNS Functions Cleanup Nameserver Config File Fatal! named.conf fails named-checkconf, please repair named.conf and try again
options { default-key "rndc-key"; default-server 127.0.0.1; default-port 953; }; # End of rndc.conf
# Use with the following in named.conf, adjusting the allow list as needed: #key "rndc-key" { # algorithm hmac-md5; # secret "KLGSBmWZrev0I4fR4Tm4GXxdcYSTFzF23b1f9is1M="; #}; # # controls { # inet 127.0.0.1 port 953 # allow { 127.0.0.1; } keys { "rndc-key"; }; # }; # End of named.conf Then i took a look at named.conf
Code: options { /* make named use port 53 for the source of all queries, to allow * firewalls to block all ports except 53: */
//query-source port 53;
/* We no longer enable this by default as the dns posion exploit has forced many providers to open up their firewalls a bit */
// Put files that named is allowed to write in the data/ directory: directory "/var/named"; // the default pid-file "/var/run/named/named.pid"; dump-file "data/cache_dump.db"; statistics-file "data/named_stats.txt"; /* memstatistics-file "data/named_mem_stats.txt"; */ };
logging { /* If you want to enable debugging, eg. using the 'rndc trace' command, * named will try to write the 'named.run' file in the $directory (/var/named"). * By default, SELinux policy does not allow named to modify the /var/named" directory, * so put the default debug log file in data/ : */ channel default_debug { file "data/named.run"; severity dynamic; }; };
// All BIND 9 zones are in a "view", which allow different zones to be served // to different types of client addresses, and for options to be set for groups // of zones. // // By default, if named.conf contains no "view" clauses, all zones are in the // "default" view, which matches all clients. // // If named.conf contains any "view" clause, then all zones MUST be in a view; // so it is recommended to start off using views to avoid having to restructure // your configuration files in the future.
view "localhost_resolver" { /* This view sets up named to be a localhost resolver ( caching only nameserver ). * If all you want is a caching-only nameserver, then you need only define this view: */ match-clients { 127.0.0.0/24; }; match-destinations { localhost; }; recursion yes;
zone "." IN { type hint; file "/var/named/named.ca"; };
/* these are zones that contain definitions for all the localhost * names and addresses, as recommended in RFC1912 - these names should * ONLY be served to localhost clients: */ include "/var/named/named.rfc1912.zones"; };
I'd like to add geodns to BIND, so I need to modify named.conf. All that I will put into is a include of an acl file (for different IP ranges), and add a new view for existed domain.
My VPS use cPanel. What is the best way to handle this, as named.conf can be modify by cPanel? I can modify the template in /scripts/rebuilddnsconfig, but I don't know how to add a new view.
There's only one site in my VPS. But I use a few subdomains in DNS (legacy issues). Only one db file in /var/named/
I have the following problem: When i try to restart the nameserver service i get the following error:
# service named restart Stopping named: [ OK ] Starting named: Error in named configuration: /etc/named.conf:87: unknown option 'e' /etc/named.conf:120: unexpected end of input [FAILED] my named.conf as follows:
options { /* make named use port 53 for the source of all queries, to allow * firewalls to block all ports except 53: */ query-source port 53;
// Put files that named is allowed to write in the data/ directory: directory "/var/named"; // the default dump-file "data/cache_dump.db"; statistics-file "data/named_stats.txt"; /* memstatistics-file "data/named_mem_stats.txt"; */ };
logging { /* If you want to enable debugging, eg. using the 'rndc trace' command, * named will try to write the 'named.run' file in the $directory (/var/named). * By default, SELinux policy does not allow named to modify the /var/named directory, * so put the default debug log file in data/ : */ channel default_debug { file "data/named.run"; severity dynamic; }; };
// All BIND 9 zones are in a "view", which allow different zones to be served // to different types of client addresses, and for options to be set for groups // of zones. // // By default, if named.conf contains no "view" clauses, all zones are in the // "default" view, which matches all clients. // // If named.conf contains any "view" clause, then all zones MUST be in a view; // so it is recommended to start off using views to avoid having to restructure // your configuration files in the future.
view "localhost_resolver" { /* This view sets up named to be a localhost resolver ( caching only nameserver ). * If all you want is a caching-only nameserver, then you need only define this view: */ match-clients { 127.0.0.0/24; }; match-destinations { localhost; }; recursion yes;
zone "." IN { type hint; file "/var/named/named.ca"; };
// include "/var/named/named.rfc1912.zones"; // you should not serve your rfc1912 names to non-localhost clients.
// These are your "authoritativ zone "smpl.splinteredmedia.net" { type master; file "/var/named/smpl.splinteredmedia.net.db"; };
e" internal zones, and would probably // also be included in the "localhost_resolver" view above : };
view "external" { /* This view will contain zones you want to serve only to "external" clients * that have addresses that are not on your directly attached LAN interface subnets: */
recursion no; // you'd probably want to deny recursion to external clients, so you don't // end up providing free DNS service to all takers
// all views must contain the root hints zone: zone "." IN { type hint; file "/var/named/named.ca"; };
// These are your "authoritative" external zones, and would probably // contain entries for just your web and mail servers:
// BEGIN external zone entries
};
z zone "smpl.splinteredmedia.net" { type master; file "/var/named/smpl.splinteredmedia.net.db"; };
i had install cpanel on Cent Os 5 on a VPS Cpanel Correctly Running but named does not working ! i try to restart named but it say : root@server [/etc]# service named restart Stopping named: [ OK ] Starting named: Error in named configuration: none:0: open: /etc/named.conf: file not found [FAILED]
I'm getting this warning from check server security option in csf : -------- You have a local DNS server running but do not have any recursion restrictions set in /etc/named.conf. This is a security and performance risk and you should look at restricting recursive lookups to the local IP addresses only -------- I saw named.conf but In fact I didn't understand what should I do Can somebody tells me what should i do and what this warning trying to tell me?
After Cpanel update latest release version. I have issue with named.conf. I tried to rebuild named. but..
/scripts/rebuilddnsconfig fixrndc requires a syntactically correct /etc/named.conf. No changes were made to /etc/named.conf.
Problem was:
/etc/named.conf:23: when using 'view' statements, all zones must be in views Anyone can explain me about "/etc/named.conf:23: when using 'view' statements, all zones must be in views"?
So why does it still say Connection: Keep-Alive? I know that if its off, it should say Connection: Closed. And where did the timeout=1 and max=100 come from?
My httpd.conf Timeout 90 KeepAlive Off KeepAliveTimeout 15 KeepAliveRequests 10
HTTP headers is reporting Keep-Alive: timeout=1, max=100 Connection: Keep-Alive
I see some errors about lame servers in messages log,and i noticed that look like adress of isp surfer domain beacuse i noticed domain of my isp listed also as lame name server.Here is example:
Nov 24 03:46:55 available9 named[7562]: lame server resolving '247.100.51.72.in-addr.arpa' (in '100.51.72.in-addr.arpa'?): 205.214.192.202#53 Nov 24 03:46:55 available9 named[7562]: lame server resolving '247.100.51.72.in-addr.arpa' (in '100.51.72.in-addr.arpa'?): 205.214.192.201#53 Nov 24 03:46:56 available9 named[7562]: lame server resolving '247.100.51.72.in-addr.arpa' (in '100.51.72.in-addr.arpa'?): 205.214.192.202#53 Nov 24 03:46:56 available9 named[7562]: lame server resolving '247.100.51.72.in-addr.arpa' (in '100.51.72.in-addr.arpa'?): 205.214.192.201#53 Nov 24 07:19:51 available9 named[7562]: FORMERR resolving 'ducksimilar.com/NS/IN': 203.93.208.87#53 Nov 24 07:19:51 available9 named[7562]: FORMERR resolving 'ducksimilar.com/NS/IN': 91.208.228.150#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host1.experienceexcept.com/AAAA/IN': 203.93.208.87#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host2.experienceexcept.com/AAAA/IN': 203.93.208.87#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host1.experienceexcept.com/AAAA/IN': 91.208.228.150#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host2.experienceexcept.com/AAAA/IN': 91.208.228.150#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host1.experienceexcept.com/AAAA/IN': 203.93.208.87#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host2.experienceexcept.com/AAAA/IN': 203.93.208.87#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host1.experienceexcept.com/AAAA/IN': 91.208.228.150#53 Nov 24 07:19:52 available9 named[7562]: FORMERR resolving 'host2.experienceexcept.com/AAAA/IN': 91.208.228.150#53
It has been a long time since I setup named, and I need some help as I'm just not getting it this time around. I'm running named on CentOS under Chroot
IP Space is; 216.201.80.96/28 Gateway is 216.201.80.97 Netmask is 255.255.255.240 Useable IP Space is 216.201.80.100 - 110
named.conf --- key "rndckey" { algorithm hmac-md5; // secret is xx'ed out for this posting secret "xxxxxxxxxxxxxx"; };
zone "cheapdatamining.com" IN { type master; file "data/cheapdatamining.com.zone"; allow-update { none; }; };
cheapdatamining.com.zone -------------------------- $TTL 38400 @ IN SOA ns1.cheapdatamining.com. admin.cheapdatamining.com ( 2008090335 ; Serial 10800 ; Refresh after 3 hours 3600 ; Retry after 1 hour 604800 ; Expire after 1 week 86400 ) ; Minimum TTL 1 day
cheapdatamining.com.INNS ns1.cheapdatamining.com. cheapdatamining.com.INNSns2.cheapdatamining.com. ns1.cheapdatamining.com.IN A 216.201.80.101 ns2.cheapdatamining.com. IN A 216.201.80.102
resolv.conf on server. -------------- search cheapdatamining.com nameserver 216.201.80.101 nameserver 216.201.80.102
Got the domain sitting at godaddy with ns1 and ns2 pointing to 216.201.80.101/102
Everything looks good as far as I can see, local nslookup on the loopback is fine, and iptables are good.
Now we host about 100,000 domains and they are all using the same DNS servers (cPanel cluster system)
So now I checked our /etc/named.conf files.. and these are HUUUGE.. If you try to start/restart named service it takes 5 minutes to load all zones. It is also taking about 30% CPU and 35% of ram when running even on dual core server..
Any ideas how could we optimise named configuration ? Maybe it is something like mod_vhost_alias for Apache just for bind service?
Code: root@saturn [~]# service named start Starting named: Error in named configuration: /etc/named.conf:33: expected IP address near ';' [FAILED] And when I look for the problem:
Code: root@saturn [~]# grep named /var/log/messages | tail -10 Apr 1 17:10:16 saturn named: failed Apr 1 17:10:16 saturn named: /etc/named.conf:33: expected IP address near ';' Apr 1 17:14:27 saturn named: failed Apr 1 17:14:28 saturn named: failed Apr 1 17:14:28 saturn named: /etc/named.conf:33: expected IP address near ';' Apr 1 17:22:51 saturn named: failed Apr 1 17:22:51 saturn named: failed Apr 1 17:22:51 saturn named: /etc/named.conf:33: expected IP address near ';' Apr 1 17:28:15 saturn named: failed Apr 1 17:28:15 saturn named: /etc/named.conf:33: expected IP address near ';'
[root@server etc]# service named restart Stopping named: [FAILED] Starting named: Error in named configuration: zone localdomain/IN: loaded serial 42 zone localhost/IN: loaded serial 42 zone 0.0.127.in-addr.arpa/IN: loaded serial 1997022700 zone 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 1997022700 zone 255.in-addr.arpa/IN: loaded serial 42 zone 0.in-addr.arpa/IN: loaded serial 42 zone server.mojaty4host.com/IN: loaded serial 2007070601 zone agr7.org/IN: loaded serial 2007070701 zone ahha1.com/IN: loaded serial 2007070701 zone i-artt.com/IN: loaded serial 2007070701 zone egyeye.com/IN: loaded serial 2007070701 zone mojaty.net/IN: loaded serial 2007070701 zone mgirlseduepmatir.com/IN: loaded serial 2007070701 zone mojaty.com/IN: loaded serial 2007070701 zone mojaty4host.com/IN: loaded serial 2007072800 zone omrnajd.com/IN: loaded serial 2007070701 zone sakervb.net/IN: loaded serial 2007070701 zone 5thdth.com/IN: loaded serial 2007070701 zone x454x.com/IN: loaded serial 2007070701 zone z5555z.com/IN: loaded serial 2007070701 zone domains.mojaty4host.com/IN: loaded serial 2007070801 zone server.mojaty4host.com.zz/IN: loaded serial 2007070801 zone voodafone.org/IN: loaded serial 2007071001 zone njoomcam.com/IN: loaded serial 2007071201 zone cokedown4host.com/IN: loaded serial 2007071301 zone q84cam.com/IN: loaded serial 2007071501 zone golden4web.com/IN: loaded serial 2007071501 zone tsmymat.com/IN: loaded serial 2007071601 zone chat.mojaty4host.com/IN: loaded serial 2007072501 zone reemando.com/IN: loaded serial 2007071701 zone khaleejstudent.com/IN: loaded serial 2007071701 zone amwaj3.com/IN: loaded serial 2007071701 zone academy-love.com/IN: loaded serial 2007071801 zone alrsamhost.net/IN: loaded serial 2007071801 zone new-lock.com/IN: loaded serial 2007071801 zone yutmah.com/IN: loaded serial 2007071801 zone ksa-stars.com/IN: loaded serial 2007071801 zone gold4shop.com/IN: loaded serial 2007071901 zone xhamsx.com/IN: loaded serial 2007071901 zone ithadyfans.com/IN: loaded serial 2007071901 zone banat-alriffa3.com/IN: loaded serial 2007071901 zone kingawy.net/IN: loaded serial 2007072201 zone ateaf-host.com/IN: loaded serial 2007072401 zone ns1.dr-nokia4host.com/IN: loaded serial 2007072301 zone ns2.dr-nokia4host.com/IN: loaded serial 2007072301 zone dr-nokia.org/IN: loaded serial 2007072501 zone k0s0a.com/IN: loaded serial 2007072701 zone hiarab4ever.net/IN: loaded serial 2007072801 zone ayam7.com/IN: loaded serial 2007072901 zone gulf-pixel.com/IN: loaded serial 2007080900 zone sa-club.com/IN: loaded serial 2007073101 zone sharjah1.org/IN: loaded serial 2007080201 zone al-doseri.net/IN: loaded serial 2007080301 zone alnouami.com/IN: loaded serial 2007080301 zone sharjah1.com/IN: loaded serial 2007080301 zone shababz.com/IN: loaded serial 2007080301 zone ahat-naif.com/IN: loaded serial 2007080501 zone al5yaal.net/IN: loaded serial 2007080508 zone cssarabia.com/IN: loaded serial 2007080501 zone hashlangroup.com/IN: loaded serial 2007080501 zone hot-w-groub.com/IN: loaded serial 2007080501 zone sa1tan.com/IN: loaded serial 2007080502 zone takinty.com/IN: loaded serial 2007080501 zone uaeksa.com/IN: loaded serial 2007080501 zone web2.mojaty4host.com/IN: loaded serial 2007080501 zone web3.mojaty4host.com/IN: loaded serial 2007080501 zone web4.mojaty4host.com/IN: loaded serial 2007080501 zone llwowll.com/IN: loaded serial 2007080601 zone ea4net.com/IN: loaded serial 2007080901 zone backup.com/IN: loaded serial 2007080901 zone 2qq7.com/IN: loaded serial 2007080901 zone 3kalam.net/IN: loaded serial 2007080901 zone 7laksa.net/IN: loaded serial 2007080901 zone 9habab.com/IN: loaded serial 2007080901 zone al-hidyaway.com/IN: loaded serial 2007080901 zone alkharjxp.com/IN: loaded serial 2007080901 zone alraass.com/IN: loaded serial 2007080901 zone alslbokhi.com/IN: loaded serial 2007080901 zone anamluae.com/IN: loaded serial 2007080901 zone b3z3.com/IN: loaded serial 2007080901 zone r3boob.net/IN: loaded serial 2007080901 zone banatcrazy.com/IN: loaded serial 2007080901 zone d3eenn.com/IN: loaded serial 2007080901 dns_master_load: /var/named/domoo3-7a2era.com.db:7: unexpected end of line dns_master_load: /var/named/domoo3-7a2era.com.db:6: unexpected end of input dns_master_load: /var/named/domoo3-7a2era.com.db:9: unexpected end of line dns_master_load: /var/named/domoo3-7a2era.com.db:8: unexpected end of input dns_master_load: /var/named/domoo3-7a2era.com.db:10: isc_lex_gettoken() failed: unbalanced parentheses dns_master_load: /var/named/domoo3-7a2era.com.db:10: unbalanced parentheses zone domoo3-7a2era.com/IN: loading master file /var/named/domoo3-7a2era.com.db: unexpected end of input _default/domoo3-7a2era.com/IN: unexpected end of input zone emprie-romance.com/IN: loaded serial 2007080901 zone essa-alharthy.com/IN: loaded serial 2007080901 zone fnon2.com/IN: loaded serial 2007080901 zone gahrr.com/IN: loaded serial 2007080901 zone hamsat14.com/IN: loaded serial 2007080901 zone hilali-fans.net/IN: loaded serial 2007080901 zone imam-shafie.com/IN: loaded serial 2007080901 zone jameiah.com/IN: loaded serial 2007080901 zone juvepersempre.com/IN: loaded serial 2007080901 zone l1n1.net/IN: loaded serial 2007080901 zone mjnonha.com/IN: loaded serial 2007080901 zone m-al7lween.com/IN: loaded serial 2007080901 zone qalak.com/IN: loaded serial 2007080901 zone qloob30.com/IN: loaded serial 2007080901 zone quraishat.com/IN: loaded serial 2007080901 zone raayse.com/IN: loaded serial 2007080901 zone romance-empire.com/IN: loaded serial 2007080901 zone roo7oman.com/IN: loaded serial 2007080901 zone rooo3h.net/IN: loaded serial 2007080901 zone roz-nada.com/IN: loaded serial 2007080901 zone seafx.com/IN: loaded serial 2007080901 zone shaagran.net/IN: loaded serial 2007080901 zone shwg.net/IN: loaded serial 2007080901 zone sqalb.com/IN: loaded serial 2007080901 zone stars6.com/IN: loaded serial 2007080901 zone v1111v.com/IN: loaded serial 2007080901 zone w998w.com/IN: loaded serial 2007080901 zone zkirt.com/IN: loaded serial 2007080901 zone a88888a.mojaty4host.com/IN: loaded serial 2007081001 zone acefhost.com/IN: loaded serial 2007081001 zone trtshly.com/IN: loaded serial 2007081001 zone n1n9.com/IN: loaded serial 2007062602 zone ya-gro7i.com/IN: loaded serial 2007081003 zone q-almjroh.com/IN: loaded serial 2007081001 zone u88p.com/IN: loaded serial 2007081001 zone dnadesh.net/IN: loaded serial 2007081001 zone 3atr.net/IN: loaded serial 2007081101 zone acefalmhrh.biz/IN: loaded serial 2007081101 zone al-trf.net/IN: loaded serial 2007081101 zone fn-fn.com/IN: loaded serial 2007081101 zone dl8l.com/IN: loaded serial 2007081101 zone sport-fifa.com/IN: loaded serial 2007081101 zone laamst.com/IN: loaded serial 2007081101 zone 3malka.com/IN: loaded serial 2007081101 zone acefalmhrh.net/IN: loaded serial 2007081101 zone aryweb.com/IN: loaded serial 2007081101 zone b77w.com/IN: loaded serial 2007081101 zone 500100100.net/IN: loaded serial 2007081101 zone soly-vb.com/IN: loaded serial 2007081101 zone rap-boyz.net/IN: loaded serial 2007081101 zone 3rb-islam.com/IN: loaded serial 2007081101 zone roz-vip.com/IN: loaded serial 2007081101 zone tknlujia-serv.com/IN: loaded serial 2007081101 zone gr7gr7.com/IN: loaded serial 2007081101 zone h-bnat.com/IN: loaded serial 2007081101 zone 2wgat.com/IN: loaded serial 2007081101 zone al5aleej.net/IN: loaded serial 2007081101 zone ala7asees.com/IN: loaded serial 2007081101 zone k7chat.com/IN: loaded serial 2007081101 zone 3albaal.com/IN: loaded serial 2007081101 zone alyakota.com/IN: loaded serial 2007081101 zone lootss.net/IN: loaded serial 2007081101 zone acef-des.com/IN: loaded serial 2007081101 zone almosabqat.com/IN: loaded serial 2007081101 zone hacker4ever.net/IN: loaded serial 2007081101 zone muza1.com/IN: loaded serial 2007081101 [FAILED] [root@server etc]#
What is the solution to this problem
Tried where many do not benefit you to contact technical support cpanel
Well the last week my server has experimenting a big load on some hours of the day and every deay ....
all looks goods , few TIME_WAIT packages , few conections per ip , few process of httpd ....
when I check with a: tail -f /var/log/messages appears a lot of this lines
Aug 29 17:28:49 server kernel: Firewall: *UDP_IN Blocked* IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:2f:87:27:83:08:00 SRC=190.8.82.204 DST=255.255.255.255 LEN=75 TOS=0x00 PREC=0x00 TTL=128 ID=27592 PROTO=UDP SPT=8782 DPT=9777 LEN=55 Aug 29 17:28:54 server kernel: printk: 33 messages suppressed. Aug 29 17:28:55 server kernel: Neighbour table overflow. Aug 29 17:28:58 server last message repeated 3 times Aug 29 17:29:23 server named[1949]: client 209.244.7.40#5302: error sending response: not enough free resources Aug 29 17:29:27 server last message repeated 2 times Aug 29 17:29:24 server kernel: Neighbour table overflow. Aug 29 17:29:29 server named[1949]: client 209.244.7.40#5302: error sending response: not enough free resources Aug 29 17:29:31 server named[1949]: client 209.244.7.40#5302: error sending response: not enough free resources Aug 29 17:29:34 server kernel: Neighbour table overflow. Aug 29 17:29:35 server last message repeated 3 times Aug 29 17:29:35 server named[1949]: client 200.225.157.203#32841: error sending response: not enough free resources Aug 29 17:29:35 server kernel: Neighbour table overflow. Aug 29 17:29:35 server named[1949]: client 200.225.157.203#32841: error sending response: not enough free resources Aug 29 17:29:36 server kernel: Neighbour table overflow. Aug 29 17:29:36 server named[1949]: client 200.225.157.203#32841: error sending response: not enough free resources Aug 29 17:29:36 server kernel: Neighbour table overflow. Aug 29 17:29:36 server named[1949]: client 200.225.157.203#32841: error sending response: not enough free resources
this could be an atack? because appears a lot of differents ip and they try to access in differnts ports..
Has anyone noticed recently on a fresh cPanel install that named doesn't start by itself on a reboot? I have had to chkconfig named on on every cPanel install I've done on a CentOS box in the last 2 months.
Since yesterday named started to use more cpu than usual. Techs "refuse" to work with that issue and saying that its's normal. Though all the time had no problems, haven't added hundreds of domains yesterday and there were no changes from my end.
There was one change from techs side however.
"the MX record for the domain was going to localhost, rather than the domain name. I have changed the MX record to domain..."
Anything I should check? Logs doesn't provide anything valuable, just notices.
the DNS Server never resolves, i create one account on my server, i put the nameservers... about 6 Hours ago and nothing, i setup the Domain DNS and nothing, what can be? how i can fix this?