LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-15-2004, 04:14 AM   #1
freelinuxcpp
Member
 
Registered: Jul 2003
Posts: 129

Rep: Reputation: 15
Best OS for a BEST DNS server


hello every 1
i wanna hear ur point of view about a DNS server i want to set
firstly i have to shose a good OS for this , i m used to use many Linux distro and also a *BSD one , but for the most secure / good performance DNS server i dont really what to shose , i m thaught about debian , but i found multiple vulnerability on each version , then i thought about openBSD whish has a good security reputation , but don't really know if it's as faster as debian linux ......
any advices are welcome
 
Old 02-15-2004, 04:38 AM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Well with DNS servers, generally you don't have a lot of disk IO as the DNS cache is written to memory. However, if you update the records a lot that could cause significant IO. Depending on how busy the system will be and how much it will have to access disk, that may or may not be a consideration for the OS (how fast can different OSs access disk under very high load).

In generally for a DNS server you want:
Something with very good security (it's going to be highly visible and accessible)
Excellent network performance

Personally, I recommend OpenBSD for any system that needs to be highly exposed. In some benchmarks, OpenBSD didn't do as well as other systems in performance, but many of those tests simulated conditions more like serving a large amount of web pages, and also the way the tests were constructed and controlled was very poor, so the results can't be trusted that much.

OpenBSD can handle network conditions very well (you can use the built-in packet filter to protect against SYN floods, prioritize traffic, etc). It also chroot's BIND by default (if you choose to go with BIND), and it supports DJBDNS if you don't want to use BIND.

Other choices might be FreeBSD or NetBSD, since they both have excellent performance and also have their own packet filters.

You could use Linux, although you would want to find a distro that installs very few packages by default and has a good security record. A lot of the Linux distros install a very excessive amount of software packages by default, and some of the common applications link against a huge number of unnecessary libraries. If you choose to go with Linux, be extremely careful and make sure to thoroughly harden the system before you attach it to the network.

OpenBSD and NetBSD don't have nearly as many problems as most Linux distros, because they only install a few applications by default, and all the dangerous network daemons are in the most secure configuration by default.

Last, if SMP is a requirement, then you'll need to use FreeBSD, NetBSD, or Linux as OpenBSD doesn't support it (but generally one very fast processor does better than a couple of slightly slower CPUs, and would you really need SMP for a DNS server?).

Last edited by chort; 02-15-2004 at 04:41 AM.
 
Old 02-15-2004, 08:55 PM   #3
german
Member
 
Registered: Jul 2003
Location: Toronto, Canada
Distribution: Debian etch, Gentoo
Posts: 312

Rep: Reputation: 30
OpenBSD. Easy and fast if you aren't scared of writing master zone records by hand.

B.
 
Old 02-16-2004, 06:02 AM   #4
freelinuxcpp
Member
 
Registered: Jul 2003
Posts: 129

Original Poster
Rep: Reputation: 15
well first thanx for the replys ,
i guess i ll use debian or open bsd, debian by default installs very few packages when we precise a basic installation , and it's bind9 seems to be as performante as any other linux distro
i have a Compaq ML370 machine i don't know if this is compatible with openBSD , at the end i have to test it before , i also think to write a script to add , remove zone automatically !
y the way i don't scare about
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
dns client cannot resolve on dns server jtvillegas Linux - Software 3 03-12-2016 03:30 PM
help needed to setup a DNS server can anyone say how to configure a DNS server subha Linux - Networking 4 04-27-2012 11:50 PM
How the DNS-server is connected to work of a web-server and a mail-server? ukrainet Linux - Newbie 2 01-10-2005 09:18 PM
Do I leave primary and seconday DNS blank for a DNS Server? imsam Linux - Networking 3 10-25-2004 01:48 PM
need help to set up caching only dns server to with bogus DNS entries ullas Linux - Networking 1 10-28-2003 01:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration