Answer the question
In order to leave comments, you need to log in
Why are some of the responses from the internal DNS server empty (ServFail)?
Given:
Local network for 100 machines
Gateway running Debian 7 i386 with two network
ports A caching dns server is installed on the gateway
Internet access channel 15Mbps, twisted pair to the provider's router.
Clients: Windows XP, 7, Ubuntu, Debian.
Problem: Are some of the responses from the internal DNS server empty (ServFail)?
Access to internet sites is very difficult.
Conditions: Out of business
hours, the problem is not observed.
When observing the problem:
Server load
dig command to the server
Local interface load Load of the interface to the tcpdump
provider on port 53 of the local interface Powerdns-server statistics
List of unsuccessful attempts to solve the problem:
1. Pure Ubuntu on the gateway instead of Debian.
2. pdns-server + pdns-recursor instead of dnsmasq
3. squid with filters instead of direct internet access
4. Gateway on real hardware instead of virtual machine
Thanks in advance for your valuable advice
Answer the question
In order to leave comments, you need to log in
You don't need to look at statistics, but enable pdns logs.
servfail should always be logged.
[SOLVED] On each server, the iptables add-on blocked udp connections by default over the set limit. Cured by disabling the limit
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question