The root servers are always the starting point for any new query cycle, which makes them the critical part of the critical infrastructure! Using anycast techniques, these servers are replicated across the globe.

There are now well over 100 instances of the various root-servers in operational use, the majority of which now lie outside North America.

by Ron Aitchison 04/26/2007 Here are five things you can do to make sure your DNS is in good shape and not causing problems for the rest of the Internet, which, by the way, also includes you.

Every time we get email, access a web page, make a Vo IP call, or complete many other tasks, we use the Domain Name System (DNS).

These suggestions have been tested on Fedora Core 3 and Core 4.

If you find any errors or have any suggestions regarding this information please feel free to E-mail me at [email protected]

Sometimes it also useful to be able to start with an IP address and find the name allocated to it; email systems especially use this technique as part of an antispam arsenal.The root-servers receive more than 2 billion queries per day, of which (according to some studies [6],) only 2% are legitimate queries!While the vast majority of unnecessary traffic relates to buggy software and badly configured firewalls, a significant proportion was caused by poorly configured DNS software.So with all this information at our fingertips, let's look at five DNS issues that you should check to minimize unnecessary traffic on the DNS infrastructure, and help keep your organization running smoothly.Up to 7% of the total traffic arriving at some root servers consists of reverse queries for private IP addresses, and a complete routing infrastructure (AS112) has been constructed just to handle this problem.Power DNS offers full master and slave semantics for replicating domain information.Furthermore, Power DNS can benefit from native database replication.I like to consider myself a DNS/BIND expert, but it just goes to show that you can learn something new everyday.I setup my secondary DNS servers for both and my personal domain in the way that I always have.That makes DNS part of the critical infrastructure of the Internet.This article describes five things that you can do to keep you and your organization safe as well as reduce unnecessary load on the DNS infrastructure: ) or zone file fragments are included.


  1. Mar 19, 2012. Reason Administrator could not configure a slave DNS server as it cannot function properly unless SOA serial number is changed every time a DNS record is changed. Result if any bind-dyndb-ldap plugin used to provision data from Identity Management DNS tree to the BIND Name Server updates DNS.

  2. Native replication basically means that PowerDNS will not send out DNS update notifications, nor will react to them. For the BIND backend, the native BIND configuration language suffices to specify multiple masters, for SQL based backends, list all master servers separated by commas in the 'master' field of the domains.

  3. Jul 8, 2016. If you intend to serve a registered domain name they ensure that your DNS zone is still available even if your primary server is not online. The zone file must be in /var/cache/bind/ because, by default, AppArmor only allows write access inside it this was made specifically for a slave configuration.

