LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-18-2022, 08:00 AM   #1
fruitwerks
Member
 
Registered: Apr 2009
Posts: 80

Rep: Reputation: 15
ISC Bind/named "timed out resolving"


I am going crazy with this. Out of nowhere, I started getting the error "timed out resolving". Nothing has changed and this configuration has been rock solid for many years. That said, it is Ubuntu 20 LTS and up-to-date.

I have a fairly vanilla configuration of Bind with root hints disabled and forwarding to Google DNS. The purpose of this server is to handle all DNS queries on my network and forward anything that isn't local.

Oddly, tcpdump shows a successful query to the upstream nameserver but bind will randomly say it timed out resolving. I have tried a handful of upstream servers and this makes no difference. If I run dig or nslookup directed at the server and domain that has allegedly failed, I get a speedy response.

I enabled query error logging and that is blank. I have checked my firewall and routing machine. I have power-cycled all of the core equipment to no avail. As I mentioned, nothing has changed recently and this configuration has worked for years.

And if anyone was wondering, it is not an internet issue or physical network issue. Pings, iperf and all that are performing as expected with zero loss.

Thanks!
 
Old 12-18-2022, 09:57 AM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,155

Rep: Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266Reputation: 1266
Make sure you are only serving local queries and not for the general internet. Also check you aren't being attacked. Typically, UDP packets are not lost in transit, but when buffers are full at the client. Do you have a lot of other network traffic?
 
Old 12-18-2022, 10:59 AM   #3
fruitwerks
Member
 
Registered: Apr 2009
Posts: 80

Original Poster
Rep: Reputation: 15
Thanks for the reply.

Let me clarify, I have a zonefile of blocked hosts and known locahosts. These are checked first and if there is no match it is forwarded to known DNS servers. I do have a lot of requests but not a lot of continuous traffic. I have about 120 devices that need DNS. I did check and I can't find any kernel value that is coming close to maxing out. If I watch tcpdump I can see the query is made and succeeds, but bind says it time out. There is nothing getting dropped on any firewalls.

I'm ready to ditch named since it has already been replaced by Kea and it doesn't look like a good alternative as it is not a drop-in. I had to fire up unbound for the moment but I can already tell it is not a great fit either. Unbound has not failed to resolve anything valid (except LAN member lookups) as far as I can tell.

I need something that can resolve local hosts, block from my list, and reach out to external DNS if the request isn't satisfied.
 
Old 12-18-2022, 11:39 AM   #4
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,173
Blog Entries: 1

Rep: Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040Reputation: 2040
Quote:
I need something that can resolve local hosts, block from my list, and reach out to external DNS if the request isn't satisfied.
Take a look at dnsmasq that can block domains/hosts from a list and forward queries to specified forwarders.

Regards
 
Old 12-18-2022, 11:52 AM   #5
fruitwerks
Member
 
Registered: Apr 2009
Posts: 80

Original Poster
Rep: Reputation: 15
I used dnsmasq briefly long ago. I don't know if it was the build/version or the hardware, that too gave me trouble. It looks like Pi-Hole has matured and has everything I've been doing manually for years. I have installed it on an S922x board and appears to be keeping up. I may have a solution, but not an answer to my original inquiry.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error log: upstream timed out (110: Connection timed out) on Nginx nikaway Linux - Server 1 09-30-2015 02:43 PM
[SOLVED] USB: Connection timed out SYS: Connection timed out PeterUK Programming 3 07-18-2013 02:59 AM
(bind) named: couldn't open pid file '/var/run/named/named.pid' - any help? samengr Linux - Server 6 04-01-2009 06:22 AM
chown -R named:named /var/named crash the system? joangopan Fedora 2 09-09-2007 02:46 AM
sendmail - Connection timed out [dsn=4.0.0 stat=Deferred: Connection timed out] ananthak Linux - Software 0 04-24-2007 07:28 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration