DNS secondaire injoignable

Fermé
Colem - Modifié le 8 oct. 2019 à 10:13
brupala Messages postés 109443 Date d'inscription lundi 16 juillet 2001 Statut Membre Dernière intervention 23 avril 2024 - 8 oct. 2019 à 12:46
Salut à tous

Me voilà avec un big problème que je n'arrive pas à résoudre depuis hier.
Mon serveur DNS secondaire est en serverfail

Je pense avoir trouvé la raison mais ne voit pas pourquoi

/etc/named.conf
Le maitre
zone "domaine.biz" {
        type master;
        file "/var/named/domaine.biz.db";
        allow-update { 163.172.1.226; };
};


L'esclave
        allow-query     { any; };
        allow-notify     { 82.65.125.128; };

zone "domaine.biz" {
        type slave;
        file "/var/named/domaine.biz.db";
        masters{ 82.65.125.128; };
};


je ne mets que ce qui pour moi est important

en status bind

primaire
named.service - Berkeley Internet Name Domain (DNS)
   Loaded: loaded (/usr/lib/systemd/system/named.service; enabled; vendor preset: disabled)
   Active: active (running) since Tue 2019-10-08 09:38:35 CEST; 2s ago
  Process: 23022 ExecStop=/bin/sh -c /usr/sbin/rndc stop > /dev/null 2>&1 || /bin/kill -TERM $MAINPID (code=exited, status=0/SUCCESS)
  Process: 11823 ExecReload=/bin/sh -c /usr/sbin/rndc reload > /dev/null 2>&1 || /bin/kill -HUP $MAINPID (code=exited, status=0/SUCCESS)
  Process: 23038 ExecStart=/usr/sbin/named -u named -c ${NAMEDCONF} $OPTIONS (code=exited, status=0/SUCCESS)
  Process: 23034 ExecStartPre=/bin/bash -c if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then /usr/sbin/named-checkconf -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi (code=exited, status=0/SUCCESS)
 Main PID: 23039 (named)
   CGroup: /system.slice/named.service
           └─23039 /usr/sbin/named -u named -c /etc/named.conf

Oct 08 09:38:35 ns1.domaine.biz named[23039]: zone domaine.biz/IN: sending notifies (serial 2019100701)
Oct 08 09:38:35 ns1.domaine.biz systemd[1]: Started Berkeley Internet Name Domain (DNS).
Oct 08 09:38:35 ns1.domaine.biz named[23039]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted
Oct 08 09:38:35 ns1.domaine.biz named[23039]: resolver priming query complete


secondaire
named.service - Berkeley Internet Name Domain (DNS)
   Loaded: loaded (/usr/lib/systemd/system/named.service; enabled; vendor preset: disabled)
   Active: active (running) since Tue 2019-10-08 09:42:32 CEST; 2s ago
  Process: 20405 ExecStop=/bin/sh -c /usr/sbin/rndc stop > /dev/null 2>&1 || /bin/kill -TERM $MAINPID (code=exited, status=0/SUCCESS)
  Process: 20423 ExecStart=/usr/sbin/named -u named -c ${NAMEDCONF} $OPTIONS (code=exited, status=0/SUCCESS)
  Process: 20419 ExecStartPre=/bin/bash -c if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then /usr/sbin/named-checkconf -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi (code=exited, status=0/SUCCESS)
 Main PID: 20428 (named)
   CGroup: /system.slice/named.service
           └─20428 /usr/sbin/named -u named -c /etc/named.conf

Oct 08 09:42:32 ns2.domaine.biz named[20428]: network unreachable resolving './NS/IN': 2001:500:2d::d#53
Oct 08 09:42:32 ns2.domaine.biz named[20428]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted
Oct 08 09:42:32 ns2.domaine.biz named[20428]: resolver priming query complete
Oct 08 09:42:32 ns2.domaine.biz named[20428]: zone domaine-x.biz/IN: Transfer started.
Oct 08 09:42:33 ns2.domaine.biz named[20428]: zone domaine-y.biz/IN: Transfer started.
Oct 08 09:42:33 ns2.domaine.biz named[20428]: zone domaine.biz/IN: zone transfer deferred due to quota
Oct 08 09:42:33 ns2.domaine.biz named[20428]: zone .../IN: zone transfer deferred due to quota
Oct 08 09:42:33 ns2.domaine.biz named[20428]: zone .../IN: zone transfer deferred due to quota
Oct 08 09:42:33 ns2.domaine.biz named[20428]: zone .../IN: zone transfer deferred due to quota
Oct 08 09:42:33 ns2.domaine.biz named[20428]: zone .../IN: zone transfer deferred due to quota


Avec dig
[root@ns2 named]# dig ***@*** domaine.biz

; <<>> DiG 9.11.4-P2-RedHat-9.11.4-9.P2.el7 <<>> ***@*** domaine.biz
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34581
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 3
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;domaine.biz.              IN      SOA

;; ANSWER SECTION:
domaine.biz.       86400   IN      SOA     ns1.domaine.biz. admin.domaine.biz. 2019100800 3600 7200 1209600 86400

;; AUTHORITY SECTION:
domaine.biz.       86400   IN      NS      ns2.domaine.biz.
domaine.biz.       86400   IN      NS      ns1.domaine.biz.

;; ADDITIONAL SECTION:
ns1.domaine.biz.   14400   IN      A       82.65.125.128
ns2.domaine.biz.   14400   IN      A       163.172.1.226

;; Query time: 6 msec
;; SERVER: 82.65.125.128#53(82.64.165.178)
;; WHEN: mar. oct. 08 09:46:18 CEST 2019
;; MSG SIZE  rcvd: 155


[root@ns2 named]# dig ***@*** domaine.biz

; <<>> DiG 9.11.4-P2-RedHat-9.11.4-9.P2.el7 <<>> ***@*** domaine.biz
; (3 servers found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 86
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;domaine.biz.              IN      SOA

;; Query time: 0 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: mar. oct. 08 09:40:37 CEST 2019
;; MSG SIZE  rcvd: 45


Voyez-vous quelque chose
Avez-vous une idée ?

PS: ns2 est sur un vps scaleway et ns1 est chez moi
A voir également:

1 réponse

brupala Messages postés 109443 Date d'inscription lundi 16 juillet 2001 Statut Membre Dernière intervention 23 avril 2024 13 620
8 oct. 2019 à 10:36
Salut,
zone domaine.biz/IN: zone transfer deferred due to quota
?
0
oui j'ai bien vu et je ne comprends pas
0
brupala Messages postés 109443 Date d'inscription lundi 16 juillet 2001 Statut Membre Dernière intervention 23 avril 2024 13 620 > Colem
8 oct. 2019 à 12:46
Creuse déjà de ce côté là dans le VPS
0