Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem getting bind to work in 2.2

    Scheduled Pinned Locked Moved DHCP and DNS
    14 Posts 5 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      volkans80
      last edited by

      I also can't setup bind but i can see resulting conf file box when i create a view and select it from zone edit page.

      When i run a query it gives Server Failed now.

      I activated full logging but only starting and stopping logs are logged. I can't see query logs or why server failed.

      Any suggestion?

      1 Reply Last reply Reply Quote 0
      • K Offline
        kejianshi
        last edited by

        Services > DNS forwarder - Turn it off

        Services > DNS Resolver - Turn it on.

        DNSSEC on

        Under advanced tab at top of DNS resolver page >

        Prefetch Support

        Prefetch DNS Key Support

        Harden Glue

        Harden DNSSEC data

        All On….

        System: General Setup:

        Remove all the DNS server IP you have listed

        Allow DNS server list to be overridden by DHCP/PPP on WAN - unchecked

        Do not use the DNS Forwarder as a DNS server for the firewall  - unchecked

        Don't forget to click "save" after every page you change.

        1 Reply Last reply Reply Quote 0
        • V Offline
          volkans80
          last edited by

          Thanks for your help.

          I also found my mistake and add NS record and it works now.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator
            last edited by

            @kejianshi those are for unbound, they are asking about BIND

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            1 Reply Last reply Reply Quote 0
            • K Offline
              kejianshi
              last edited by

              haha - Thats what I get for not paying attention!  :-\

              1 Reply Last reply Reply Quote 0
              • johnpozJ Online
                johnpoz LAYER 8 Global Moderator
                last edited by

                Well the one guy thanked you. Guess he isn't paying much attention either ;) hehehe

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • K Offline
                  kejianshi
                  last edited by

                  He was being polite to the idiot (me)

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Online
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    What I don't get is if the guy just needs a mx record why not just do it in unbound

                    In the advanced section
                    local-data: "example.com. 86400 IN MX 10 mail.example.com."

                    Then there you go – mx record..

                    C:>dig example.com mx

                    ; <<>> DiG 9.10-P2 <<>> example.com mx                                   
                    ;; global options: +cmd                                                   
                    ;; Got answer:                                                           
                    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47104                 
                    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

                    ;; OPT PSEUDOSECTION:                                                     
                    ; EDNS: version: 0, flags:; udp: 4096                                     
                    ;; QUESTION SECTION:                                                     
                    ;example.com.                  IN      MX

                    ;; ANSWER SECTION:                                                       
                    example.com.            86400  IN      MX      10 mail.example.com.

                    ;; Query time: 3 msec                                                     
                    ;; SERVER: 192.168.1.253#53(192.168.1.253)                               
                    ;; WHEN: Thu Feb 12 06:42:38 Central Standard Time 2015                   
                    ;; MSG SIZE  rcvd: 61

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    1 Reply Last reply Reply Quote 0
                    • K Offline
                      kejianshi
                      last edited by

                      Not sure - He has probably been running BIND for years and didn't want to leave the devil he knows?

                      Nothing wrong with BIND.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Im a big fan of it as well - but seems like a lot of work to get a mx record ;)  The way I read his post pfsense was working, which I assume he was either using the resolver or forwarder with and just needed a way to get a mx record for a local domain.  Trying to install bind seems like a pain when it takes click click to get a simple mx record.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          TeddyPace
                          last edited by

                          keeping pay attention to this topic ;D ;D ;D


                          samsung galaxy A7 case
                          Samsung Galaxy Note Edge case

                          1 Reply Last reply Reply Quote 0
                          • T Offline
                            tristram
                            last edited by

                            @johnpoz:

                            What I don't get is if the guy just needs a mx record why not just do it in unbound

                            In the advanced section
                            local-data: "example.com. 86400 IN MX 10 mail.example.com."

                            Then there you go – mx record..

                            C:>dig example.com mx                                                   
                                                                                                     
                            ; <<>> DiG 9.10-P2 <<>> example.com mx                                   
                            ;; global options: +cmd                                                   
                            ;; Got answer:                                                           
                            ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47104                 
                            ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1   
                                                                                                     
                            ;; OPT PSEUDOSECTION:                                                     
                            ; EDNS: version: 0, flags:; udp: 4096                                     
                            ;; QUESTION SECTION:                                                     
                            ;example.com.                  IN      MX                               
                                                                                                     
                            ;; ANSWER SECTION:                                                       
                            example.com.            86400  IN      MX      10 mail.example.com.     
                                                                                                     
                            ;; Query time: 3 msec                                                     
                            ;; SERVER: 192.168.1.253#53(192.168.1.253)                               
                            ;; WHEN: Thu Feb 12 06:42:38 Central Standard Time 2015                   
                            ;; MSG SIZE  rcvd: 61

                            Thanks I'll give it a go. (As it happens I did what I should've done in the first place and kept the dns off the firewall.)

                            Yes, I only needed a single MX record (but now my lab is getting larger). And yes, as someone commented, I have used bind for years - but I'm always open to try new ways of skinning the virtual cat :)

                            1 Reply Last reply Reply Quote 0
                            • K Offline
                              kejianshi
                              last edited by

                              Unbound is simple - I'm sure you can handle it with ease.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.