Multi-master scenario

Phil Dibowitz phil at ipom.com
Wed Feb 2 08:49:05 UTC 2005


I'm planning to setup multi-mastering and am looking for comments:
To increase our redundancy, I'm planning on having another DNS server at
our DR (Disaster Recovery) site which will be configured as a master.
All of our slaves will then get both the IP of the current master and
this new master in its "masters { };" parameter for each one of our zones.

I then plan on having the automated system that does DNS updates
configured to update the zonefiles on both servers.

Now, as I've read the docs, this will all work - the slaves will take
info from the master with the most recent serial number that responds first.

My first question is... notifies. If all the slaves get notifies from
both masters -- will that cause any problem? Will they get confused? I'm
assuming they won't try two zone transfers, because they'll do one then
check the serial.

Anyway, currently the setup looks like:

        Hidden Master
                 |
                 |------ external-facing name servers (non-recursive)
                 |
                 |------ internal-facing name servers (recursive)

Now, our recursive name servers are slaves for our domains for a variety
of reasons (mostly political).

The only difference will be that there will be two hidden masters in the
future.

Thoughts? Comments? Concerns?

Thanks.

--
Phil Dibowitz                             phil at ipom.com
Freeware and Technical Pages              Insanity Palace of Metallica
http://www.phildev.net/                   http://www.ipom.com/

"They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety."
  - Benjamin Franklin, 1759



-- Attached file included as plaintext by Ecartis --
-- File: signature.asc
-- Desc: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFCAJQBN5XoxaHnMrsRAiGqAKCW3chVu/7jLfDop0t+8qVdQ2Ot8ACbB9RV
eLFkrD1ovt00UfIfle5zKXo=
=HOB8
-----END PGP SIGNATURE-----




More information about the bind-users mailing list