<html>
<head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">I'm still not understanding your
constraints. If *all* updates come in through Dynamic Update, then
you don't need freeze/unfreeze.<br>
<br>
- Kevin<br>
<br>
On 4/30/2014 6:47 PM, Jeronimo L. Cabral wrote:<br>
</div>
<blockquote
cite="mid:CAK7KTbj1Y6+LYCaLYePW=fBhkNUhoKXwrbZ3xc1msmLz0RmMXQ@mail.gmail.com"
type="cite">
<div dir="ltr">In office #1, the "<a moz-do-not-send="true"
href="http://company.com">company.com</a>" master zone is
updated automatically from some Windows machines inn DNS1 and in
office #2 the same zone is updated manually in DNS2 by the
administrator who shouldn't update (using freeze and unfreeze)
the master zone from office #1. This is the scenario, and we
need that a simple query to DNS1 be responded with any record
from both zones.
<div>
<br>
</div>
<div>Thanks again</div>
</div>
<div class="gmail_extra"><br>
<br>
<div class="gmail_quote">On Wed, Apr 30, 2014 at 5:54 PM, Kevin
Darcy <span dir="ltr"><<a moz-do-not-send="true"
href="mailto:kcd@chrysler.com" target="_blank">kcd@chrysler.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div text="#000000" bgcolor="#FFFFFF">
<div>Oh, I thought this was an external-versus-internal
scenario. But, this is even easier.<br>
<br>
A) One of the nameservers (pick DNS1 or DNS2) becomes a
slave (of the "stealth" variety, if you want) of the
other<br>
B) People use nsupdate to maintain the zone<br>
<br>
For security, TSIG-sign the updates. For fast change
propagation, set up NOTIFY if and as necessary.<span
class="HOEnZb"><font color="#888888"><br>
<br>
- Kevin</font></span>
<div>
<div class="h5"><br>
<br>
On 4/30/2014 4:32 PM, Jeronimo L. Cabral wrote:<br>
</div>
</div>
</div>
<div>
<div class="h5">
<blockquote type="cite">
<div dir="ltr">Dear John, this is my scenario:
<div><br>
</div>
<div>1) Office 1: people work with some machines
and fill up a local master zone "<a
moz-do-not-send="true"
href="http://company.com" target="_blank">company.com</a>"
with records in DNS1</div>
<div>2) Office 2: people works with some others
machines and fill up a local master zone "<a
moz-do-not-send="true"
href="http://company.com" target="_blank">company.com</a>"
with another records in DNS2</div>
<div><br>
</div>
<div>So both office have a different master zone.</div>
<div><br>
</div>
<div>Both offices belong to the same company, so I
need that any client PC can resolve a hostname
from "<a moz-do-not-send="true"
href="http://company.com" target="_blank">company.com</a>"
domain, independently if this record is in DNS1
or DNS2. </div>
<div><br>
</div>
<div>Thanks again, regards.</div>
<div><br>
</div>
<div>JeLo</div>
<div><br>
</div>
</div>
<div class="gmail_extra"><br>
<br>
<div class="gmail_quote">On Wed, Apr 30, 2014 at
5:21 PM, John Miller <span dir="ltr"><<a
moz-do-not-send="true"
href="mailto:johnmill@brandeis.edu"
target="_blank">johnmill@brandeis.edu</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0
0 0 .8ex;border-left:1px #ccc
solid;padding-left:1ex">
<div dir="ltr">
<div>Hi Jeronimo,<br>
<br>
</div>
<div>First of all, please just tell us the
real domain. Yes, we could try and talk
about a fictitious "<a
moz-do-not-send="true"
href="http://example.com"
target="_blank">example.com</a>" or "<a
moz-do-not-send="true"
href="http://company.com"
target="_blank">company.com</a>," but
having the real domain name lets us
actually query your nameservers.<br>
</div>
<div><br>
</div>
<div>Let me be sure I understand: you have
two DNS servers. Each of them is
authoritative for the same domain. Are
both set as master?<br>
<br>
</div>
<div>The two servers have different copies
of the zone--what's your reason for that?<br>
<br>
</div>
<div>If both servers think they are
authoritative for a zone, then they will
answer recursive queries for those zones
themselves. From the manual: <br>
<br>
"Forwarding occurs only on those queries
for which the server is not authoritative
and does not have the answer in its
cache."<br>
<br>
</div>
<div>What exactly are you trying to achieve?<br>
<br>
</div>
<div>John<br>
</div>
<div><br>
</div>
</div>
<div class="gmail_extra"><br>
<br>
<div class="gmail_quote">
<div>
<div>On Wed, Apr 30, 2014 at 3:55 PM,
Jeronimo L. Cabral <span dir="ltr"><<a
moz-do-not-send="true"
href="mailto:jelocabral@gmail.com"
target="_blank">jelocabral@gmail.com</a>></span>
wrote:<br>
</div>
</div>
<blockquote class="gmail_quote"
style="margin:0 0 0 .8ex;border-left:1px
#ccc solid;padding-left:1ex">
<div>
<div>
<div dir="ltr"><span>Dear, I would
like to ask for solution related
with DNS (bind) configuration to
allow </span><span>forward
requests to another DNS but
related with the same domain.</span><br>
<br>
<div><span>I'm asking about two
authoritative name servers
serving the same domain but
with different zone file info
on each and have one of them
forward recursive queries to
another one if first one
cannot find some particular
subdomain record that is
missing in his version of zone
file.</span><br>
</div>
<div><span><br>
</span></div>
<div><span>My named.conf.local is
as follow, but it doesn't
work:</span></div>
<div><span><br>
</span></div>
<div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">zone
"<a moz-do-not-send="true"
href="http://company.com" target="_blank">company.com</a>" {</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">
type master;</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">
file
"/etc/bind/zones/company.com.db";</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">
allow-transfer { key
"company"; };</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">
check-names ignore;</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">
forward first;</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">
forwarders { 172.16.1.1;
};</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">};</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px"><br>
</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">Thanks
a lot, </span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px"><br>
</span></font></div>
<div><font face="Helvetica,
FreeSans, Liberation Sans,
Helmet, Arial, sans-serif"
color="#333333"><span
style="line-height:17px">JeLo</span></font></div>
<div> <br>
</div>
</div>
</div>
<br>
</div>
</div>
<div>_______________________________________________<br>
Please visit <a
moz-do-not-send="true"
href="https://lists.isc.org/mailman/listinfo/bind-users"
target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a>
to unsubscribe from this list<br>
<br>
bind-users mailing list<br>
<a moz-do-not-send="true"
href="mailto:bind-users@lists.isc.org"
target="_blank">bind-users@lists.isc.org</a><br>
<a moz-do-not-send="true"
href="https://lists.isc.org/mailman/listinfo/bind-users"
target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a><br>
</div>
</blockquote>
</div>
<span><font color="#888888"><br>
<br clear="all">
<br>
-- <br>
John Miller<br>
Systems Engineer<br>
Brandeis University<br>
<a moz-do-not-send="true"
href="mailto:johnmill@brandeis.edu"
target="_blank">johnmill@brandeis.edu</a><br>
(781) 736-4619 </font></span></div>
<br>
_______________________________________________<br>
Please visit <a moz-do-not-send="true"
href="https://lists.isc.org/mailman/listinfo/bind-users"
target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a>
to unsubscribe from this list<br>
<br>
bind-users mailing list<br>
<a moz-do-not-send="true"
href="mailto:bind-users@lists.isc.org"
target="_blank">bind-users@lists.isc.org</a><br>
<a moz-do-not-send="true"
href="https://lists.isc.org/mailman/listinfo/bind-users"
target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a><br>
</blockquote>
</div>
<br>
</div>
<br>
<fieldset></fieldset>
<br>
<pre>_______________________________________________
Please visit <a moz-do-not-send="true" href="https://lists.isc.org/mailman/listinfo/bind-users" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from this list
bind-users mailing list
<a moz-do-not-send="true" href="mailto:bind-users@lists.isc.org" target="_blank">bind-users@lists.isc.org</a>
<a moz-do-not-send="true" href="https://lists.isc.org/mailman/listinfo/bind-users" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a></pre>
</blockquote>
<br>
</div>
</div>
</div>
<br>
_______________________________________________<br>
Please visit <a moz-do-not-send="true"
href="https://lists.isc.org/mailman/listinfo/bind-users"
target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a>
to unsubscribe from this list<br>
<br>
bind-users mailing list<br>
<a moz-do-not-send="true"
href="mailto:bind-users@lists.isc.org">bind-users@lists.isc.org</a><br>
<a moz-do-not-send="true"
href="https://lists.isc.org/mailman/listinfo/bind-users"
target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a><br>
</blockquote>
</div>
<br>
</div>
</blockquote>
<br>
</body>
</html>