Need Help Analyzing BIND Related syslog

Discussion in 'Server Operation' started by giganet, Aug 31, 2007.

  1. giganet

    giganet New Member

    Hello Group...

    UBUNTU 6.06
    Apache2 2.0.55
    PHP 5.1.2
    ISPConfig 2.3.2
    Shorewall 3.0.4


    In trying to get to bottom of any potential 'zone' file errors I have been using 'nano /var/log/syslog'

    After running '/etc/init.d/bind9 restart' I then run 'nano /var/log/syslog'.

    I have been reading http://www.aboutdebian.com/dns.htm, it is stated that so long as at the end of each 'zone' related line you see 'loaded serial 1' that zone had no problems.

    Below is my syslog regarding BIND:

    Code:
    Aug 31 07:39:08 giganetwireless named[2908]: starting BIND 9.3.2 -u bind -t /var/lib/named
    Aug 31 07:39:08 giganetwireless named[2908]: found 1 CPU, using 1 worker thread
    Aug 31 07:39:08 giganetwireless named[2908]: loading configuration from '/etc/bind/named.conf'
    Aug 31 07:39:08 giganetwireless named[2908]: listening on IPv4 interface lo, 127.0.0.1#53
    Aug 31 07:39:08 giganetwireless named[2908]: listening on IPv4 interface eth0, 72.169.152.211#53
    Aug 31 07:39:08 giganetwireless named[2908]: command channel listening on 127.0.0.1#953
    Aug 31 07:39:08 giganetwireless named[2908]: command channel listening on ::1#953
    Aug 31 07:39:08 giganetwireless named[2908]: zone 0.0.127.in-addr.arpa/IN: loaded serial 1
    Aug 31 07:39:08 giganetwireless named[2908]: zone 152.169.72.in-addr.arpa/IN: loaded serial 2007083005
    Aug 31 07:39:08 giganetwireless named[2908]: dns_master_load: pri.giganetwireless.com:24: www.giganetwireless.com: CNAME and other data
    Aug 31 07:39:08 giganetwireless named[2908]: zone giganetwireless.com/IN: loading master file pri.giganetwireless.com: CNAME and other data
    Aug 31 07:39:08 giganetwireless named[2908]: running
    Aug 31 07:39:08 giganetwireless named[2908]: zone 152.169.72.in-addr.arpa/IN: sending notifies (serial 2007083005)
    Aug 31 07:39:08 giganetwireless named[2908]: zone highcountryhomesofanza.com/IN: refresh: unexpected rcode (SERVFAIL) from master 72.169.152.211#53 (source 0$
    
    The above shows 'zone' 'lo' arpa receives a 'loaded serail 1' however the next 'zone' line which is the public IP arpa receives the date as its serial- this is correct isn't it??

    And I'm not sure but is 'zone giganetwireless.com' not loading corretly as it is not tagged with 'loaded serial 1'

    EDIT
    I have just found when running 'nslookup giganetwireless.com' I receive the following:

    Code:
    mailman@giganetwireless:/etc/bind$ nslookup giganetwireless.com
    Server:         72.169.152.211
    Address:        72.169.152.211#53
    
    ** server can't find giganetwireless.com: SERVFAIL[\code]
    
    If someone could provide some input regarding this or even point me to a source of information that will help me to understand the log I am looking at would be greatly appreciated. :D 
    
    Thanks for your help
    
    Regards
     
    Last edited: Aug 31, 2007
  2. falko

    falko Super Moderator Howtoforge Staff

    You didn't specofy any nameservers for your domain at your domain registrar:

    Code:
    mh1:~# dig ns giganetwireless.com
    
    ; <<>> DiG 9.2.1 <<>> ns giganetwireless.com
    ;; global options:  printcmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 10557
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
    
    ;; QUESTION SECTION:
    ;giganetwireless.com.           IN      NS
    
    ;; Query time: 5017 msec
    ;; SERVER: 213.191.92.84#53(213.191.92.84)
    ;; WHEN: Sat Sep  1 20:53:33 2007
    ;; MSG SIZE  rcvd: 37
    
    mh1:~#
     
  3. giganet

    giganet New Member

    Incorrect NS seelcted at Registrar

    Thank you Falko

    Yeah, after banging my head for a little too long I entertained myself by going back to SRSPlus to check my NS selections- turns up I had selected NS.GIGANETWIRELESS.COM which pointed to 72.22.86.163
    RATHER THAN CHOOSING
    NS1.GIGANETWIRELESS.COM pointing to 72.169.152.211

    Jeez that hleped tremendously :D



    Thank you Falko

    Regards
     

Share This Page