LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-04-2010, 04:01 PM   #1
Dig
Member
 
Registered: Nov 2009
Posts: 50

Rep: Reputation: 1
[ Answered ] Question about TSIG


Hello,

i've 2 namesevrers running bind 9 and i restricted the transfer between the master and salve through the TSIG , The transfer goes well with no problem for all zones but when i make dig axfr domain.tld @master
i got transfer failed and on the other hand master logs said that transfered denied ... anybody knows why ?
 
Old 05-04-2010, 04:31 PM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Hi,

You need
Code:
allow-transfer {x.x.x.x;};
in the zone domain.tld definition (or in the global options if you want axfr for all the zones your dns is authoritative for), where x.x.x.x is the ip of the box you want to do the zone transfer.
 
Old 05-04-2010, 04:34 PM   #3
Dig
Member
 
Registered: Nov 2009
Posts: 50

Original Poster
Rep: Reputation: 1
Thank you bathory but is that mean it dig axfr will work only with ip restriction and will not work with TSIG only without IPs ?
 
Old 05-04-2010, 04:48 PM   #4
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
If you want to use TSIG keys for zone transfers, you can use:
Code:
allow-transfer {key TSIG.key;};
and of course you have to include TSIG.key in named.conf
 
Old 05-05-2010, 02:41 PM   #5
Dig
Member
 
Registered: Nov 2009
Posts: 50

Original Poster
Rep: Reputation: 1
Thank you bathory for help , you explained how to use key or IP with allowing transfer , but my question was how to dig axfr after implement all of that as it can't be through

#dig axfr domain.tld @master

and after many research it should be like that

#dig -y key-name:key @master domain.tld axfr

and it works now

thanks again
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
need a sendmail question (what is relaying) answered extendedping Linux - Networking 1 03-19-2008 07:29 AM
noob question i need answered cooldudejz Ubuntu 4 09-21-2005 07:44 PM
Another LILO Graphic Question (never answered?) DreameR-X Slackware 2 12-17-2004 03:45 AM
Dare you answer the question, that cannot be answered! Ephemeral Linux - Wireless Networking 8 08-29-2004 06:16 PM
NEWBIE!!! needs question answered microsoft/linux Slackware 15 05-13-2004 08:57 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration