Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem getting bind to work in 2.2

    Scheduled Pinned Locked Moved DHCP and DNS
    14 Posts 5 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      kejianshi
      last edited by

      Services > DNS forwarder - Turn it off

      Services > DNS Resolver - Turn it on.

      DNSSEC on

      Under advanced tab at top of DNS resolver page >

      Prefetch Support

      Prefetch DNS Key Support

      Harden Glue

      Harden DNSSEC data

      All On….

      System: General Setup:

      Remove all the DNS server IP you have listed

      Allow DNS server list to be overridden by DHCP/PPP on WAN - unchecked

      Do not use the DNS Forwarder as a DNS server for the firewall  - unchecked

      Don't forget to click "save" after every page you change.

      1 Reply Last reply Reply Quote 0
      • V Offline
        volkans80
        last edited by

        Thanks for your help.

        I also found my mistake and add NS record and it works now.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          @kejianshi those are for unbound, they are asking about BIND

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          1 Reply Last reply Reply Quote 0
          • K Offline
            kejianshi
            last edited by

            haha - Thats what I get for not paying attention!  :-\

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              Well the one guy thanked you. Guess he isn't paying much attention either ;) hehehe

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • K Offline
                kejianshi
                last edited by

                He was being polite to the idiot (me)

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  What I don't get is if the guy just needs a mx record why not just do it in unbound

                  In the advanced section
                  local-data: "example.com. 86400 IN MX 10 mail.example.com."

                  Then there you go – mx record..

                  C:>dig example.com mx

                  ; <<>> DiG 9.10-P2 <<>> example.com mx                                   
                  ;; global options: +cmd                                                   
                  ;; Got answer:                                                           
                  ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47104                 
                  ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

                  ;; OPT PSEUDOSECTION:                                                     
                  ; EDNS: version: 0, flags:; udp: 4096                                     
                  ;; QUESTION SECTION:                                                     
                  ;example.com.                  IN      MX

                  ;; ANSWER SECTION:                                                       
                  example.com.            86400  IN      MX      10 mail.example.com.

                  ;; Query time: 3 msec                                                     
                  ;; SERVER: 192.168.1.253#53(192.168.1.253)                               
                  ;; WHEN: Thu Feb 12 06:42:38 Central Standard Time 2015                   
                  ;; MSG SIZE  rcvd: 61

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                  1 Reply Last reply Reply Quote 0
                  • K Offline
                    kejianshi
                    last edited by

                    Not sure - He has probably been running BIND for years and didn't want to leave the devil he knows?

                    Nothing wrong with BIND.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Im a big fan of it as well - but seems like a lot of work to get a mx record ;)  The way I read his post pfsense was working, which I assume he was either using the resolver or forwarder with and just needed a way to get a mx record for a local domain.  Trying to install bind seems like a pain when it takes click click to get a simple mx record.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        TeddyPace
                        last edited by

                        keeping pay attention to this topic ;D ;D ;D


                        samsung galaxy A7 case
                        Samsung Galaxy Note Edge case

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          tristram
                          last edited by

                          @johnpoz:

                          What I don't get is if the guy just needs a mx record why not just do it in unbound

                          In the advanced section
                          local-data: "example.com. 86400 IN MX 10 mail.example.com."

                          Then there you go – mx record..

                          C:>dig example.com mx                                                   
                                                                                                   
                          ; <<>> DiG 9.10-P2 <<>> example.com mx                                   
                          ;; global options: +cmd                                                   
                          ;; Got answer:                                                           
                          ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47104                 
                          ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1   
                                                                                                   
                          ;; OPT PSEUDOSECTION:                                                     
                          ; EDNS: version: 0, flags:; udp: 4096                                     
                          ;; QUESTION SECTION:                                                     
                          ;example.com.                  IN      MX                               
                                                                                                   
                          ;; ANSWER SECTION:                                                       
                          example.com.            86400  IN      MX      10 mail.example.com.     
                                                                                                   
                          ;; Query time: 3 msec                                                     
                          ;; SERVER: 192.168.1.253#53(192.168.1.253)                               
                          ;; WHEN: Thu Feb 12 06:42:38 Central Standard Time 2015                   
                          ;; MSG SIZE  rcvd: 61

                          Thanks I'll give it a go. (As it happens I did what I should've done in the first place and kept the dns off the firewall.)

                          Yes, I only needed a single MX record (but now my lab is getting larger). And yes, as someone commented, I have used bind for years - but I'm always open to try new ways of skinning the virtual cat :)

                          1 Reply Last reply Reply Quote 0
                          • K Offline
                            kejianshi
                            last edited by

                            Unbound is simple - I'm sure you can handle it with ease.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.