<div dir="auto">NXDOMAIN means that nothing exists at the node of the DNS tree that you asked about.<div dir="auto"><br></div><div dir="auto">NOERROR NODATA means the record asked for doesn't exist at that node but something does. This would be you asked for A record and that doesn't exist but MX or some other record does exist.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Dec 13, 2023, 11:29 AM Michel Diemer via bind-users <<a href="mailto:bind-users@lists.isc.org">bind-users@lists.isc.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="font-family:Arial,Helvetica,sans-serif;font-size:12px;color:#00000"> </div>
<div style="margin-top:20px;padding-top:5px">
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12px;color:#00000">
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">Dear Bind user,</div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">I am a teacher and trying to understand how dns works. I am spending hours reading various sources without finding satisfying information. For teaching purposes I have created a virtual machine with isc dhcp server and bind9 and another virtual machine that uses the first one as ics dhcp and dns server.</div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">I have disabled IPv6 by setting link-local: [] in netplan's setting.</div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">The name of the network (dns zone) is "reseau1.lan". When I "dig -4 reseau1.lan" the AUTHORITY bit is set to 1. </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">Why or when should the AUTHORITY bit set to 1 ? What does it take for nslookup to give me an authoritative answer ? </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">If I "ping xxx.reseau1.lan" I get an NXDOMAIN answer. Why NXDOMAIN and not NOERROR (NODATA) ? The domain "reseau1.lan" exists and my dns server is authoritative for this zone (SOA record) but the computer "xxx" on this domain does not. Should I use a wildcard dns record ?</div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">I have tryed to empty the list of forwarders and disable the dns cache ... should I configure a dns-resolver only for the domain reseau1.lan and then a dns forwared for external dns queries ? Or maybe configure the resolver for the lan network interface and the forwarder on the internet network interface on the dns server ?</div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">I managed to get "AUTHORITY: 1" when typing "dig -4 soa reseau1.lan" by disabling the forwarders and the cache so I guess I should configure bind per network interface. But when typing "dig -4 pc1.reseau1.lan" the AUTHORITY bit is always set to 0.</div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"> </div>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important"><br>
<img id="m_-247307659178919251embedded0" src="cid:3944472000000002embeddedImage@golive.mail"><span style="text-decoration:none">͏ </span><br>
<br>
<img id="m_-247307659178919251embedded1" src="cid:4119250999999996embeddedImage@golive.mail"></div>
<br>
<br>
<img id="m_-247307659178919251embedded2" src="cid:4303235embeddedImage@golive.mail"><span style="text-decoration:none">͏ </span>
<div dir="ltr" style="color:rgb(29,34,40);font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;outline:none!important">
<div><br>
<br>
Kind Regards,<br>
<br>
Michel Diemer</div>
</div>
</div>
</div>
-- <br>
Visit <a href="https://lists.isc.org/mailman/listinfo/bind-users" rel="noreferrer noreferrer" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from this list<br>
<br>
ISC funds the development of this software with paid support subscriptions. Contact us at <a href="https://www.isc.org/contact/" rel="noreferrer noreferrer" target="_blank">https://www.isc.org/contact/</a> for more information.<br>
<br>
<br>
bind-users mailing list<br>
<a href="mailto:bind-users@lists.isc.org" target="_blank" rel="noreferrer">bind-users@lists.isc.org</a><br>
<a href="https://lists.isc.org/mailman/listinfo/bind-users" rel="noreferrer noreferrer" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a><br>
</blockquote></div>