DNS classless address delegation setup

I'm hoping someone can help me. I'm trying to setup my Leopard server to handle DNS reverse IP lookups on our half class C address range. I think I have everything entered correctly. By default the Server Admin GUI wants to auto setup the full class C range .1 - .255. We only have .128 - .255. Our ISP has set us up as the SOA for both our zones AND the IP range 128/25.xxx.xxx.xxx.in-addr.arpa.
I've tried to create a zone file with this name (128/25.xxx.xxx.xxx.in-addr.arpa.) which of course give me issues with the "/" so I've changed the zone file name to 128-25.xxx...
And everything looks correct and no other errors but this one comes up about ignoring out of zone data:
21-Mar-2008 16:04:30.524 db.128-25.xxx.xxx.xxx.in-addr.arpa.:12: ignoring out-of-zone data (212.xxx.xxx.xxx.in-addr.arpa)
This is the only IP I care about reversing as it's our mail server.
My setup is as follows and may not be the correct approach so please correct me:
I've made an entry in publicView.conf.apple (it says not to but I get errors about using views, if I make an entry directly in named.conf)
zone "128/25.xxx.xxx.xxx.in-addr.arpa" {
type master;
file "db.128-25.xxx.xxx.xxx.in-addr.arpa.";
allow-transfer {any;};
allow-update {none;};
My Zone file looks like:
$TTL 10800
128/25.xxx.xxx.xxx.in-addr.arpa. IN SOA dns.domain.net. apurvis.domain.net. (
2008032100 ;Serial
86400 ;Refresh
3600 ;Retry
604800 ;Expire
345600 ;Negative caching TTL
128/25.xxx.xxx.xxx.in-addr.arpa. IN NS dns.domain.net.
212.xxx.xxx.xxx.in-addr.arpa. IN PTR mail.domain.net.
My ISP has setup their system to pull zone data from my DNS server. This is working fine for my domain names (zones) but not for the reverse ip.
Please help, and Thank you!

You need to match the zone name your ISP has delegated to you.
We have one customer with the same setup working (Tiger server) but we have to do it manually not through the GUI.
The named.conf and zone file should probably look something like:
zone "128-25.xxx.xxx.xxx.in-addr.arpa" {
type master;
file "db.128-25.xxx.xxx.xxx.in-addr.arpa.";
allow-transfer {any;};
allow-update {none;};
$TTL 10800
128-25.xxx.xxx.xxx.in-addr.arpa. IN SOA dns.domain.net. apurvis.domain.net. (
2008032100 ;Serial
86400 ;Refresh
3600 ;Retry
604800 ;Expire
345600 ;Negative caching TTL
128-25.xxx.xxx.xxx.in-addr.arpa. IN NS dns.domain.net.
128-25.xxx.xxx.xxx.in-addr.arpa. IN NS <ISP slave/secondary-dns name>.
???.128-25.xxx.xxx.xxx.in-addr.arpa. IN PTR dns.domain.net.
212.128-25.xxx.xxx.xxx.in-addr.arpa. IN PTR mail.domain.net.
I have used www.dnsreport.com / www.dnsstuff.com reverse lookup to see the DNS traversal ("backtrace"), but they now restrict usage a bit or you can pay to use their services.
Using that might reveal the correct name of the zone (if you don't get it working with the above name).
HTH

Similar Messages

  • "Back to my Mac isn't working properly because your DNS server isn't responding. Contact your ISP for an alternate DNS server address, and enter it in Network Preferences".

    Hi, i am trying to setup back to my mac at home but I get the error "Back to my Mac isn't working properly because your DNS server isn't responding. Contact your ISP for an alternate DNS server address, and enter it in Network Preferences".
    There is no documentation on how to solve this anywhere.
    I have an Arris router set to bridged mode which is connected to a 5th generation airport extreme. I have tried using the google dns servers instead of the one assigned by the cable company in the AE but I still get the same error.
    Any help would be much appreciated
    Kenneth

    New to BTMM, I got stung today with the silly DNS problem message. Solution:
    1) Flush DNS cache with:
    dscacheutil -flushcache;sudo killall -HUP mDNSResponder
    2)System preferences > iCloud > untick BTMM then tick it again. The warning should have disappeared.
    Edit #1
    Apologies for the noise. The warning has come back
    Edit #2
    Just found out that BTMM is not compatible with double NAT. That's not helpful.
    http://support.apple.com/kb/TS1208

  • WRT54GS question.....DNS Server address?????

    Someone please help,
              I had a problem with my wireless not working on my 2nd PC. I originally thought that it was because of that PC being old and possibly having some trojan horses or other virus's that i could not get off. I have since threw out that PC and bought a new notebook yesterday at BestBuy. I told the man from geeksquad that i was having a problem with my wireless at home. He said that if the notebook could not connect to the wireless to push the red reset button on the back of the router and start over with redownloading it on my PC.
            I have done that, but am stuck on step 8 of the wizard. I have the IP Address, Subnet Mask, and Gateway. It is now asking for DNS 1(DNS Server address). What is DNS & where would i find this? I've had this router for about 2 years, will there be any other important information that i may need when trying to connect my notebook through this router?
               Thanks for your advise.

    I did find the DNS address's, but once i tried to finish the setup of the router it said, Unable to configure router, reset the router to factory default settings. Well in short, after some searching, i wired the PC directly to the modem. It would not connect to the internet. Did I do something or delete something I shouldn't have? Looks like it. UGH!! My notebook is working just fine connected directly to the modem, but I'm getting nothing with the PC connected to the modem or the router.
    ANYONE HELP???????

  • Where do I get DNS server addresses?

    We just upgraded a new 100 mbyte broadband modem and the AirPort Express  doesn't seem to be recognizing it. The light just keeps flashing orange
    The setup assistant says I don't have any DNS server addresses . Where do I get these?

    Did you reset the Express to factory settings and then run the assistant? - it should pick up the settings from the modem automatically - also is the modem just a modem or a wireless router also?

  • Purchased ipad already got apple id through itunes and iphone but it is not an email address ipad setup process will not allow me to use current id or change id to primary email address - do i have to have different id for ipad

    Purchased an ipad but already got apple id through itunes and iphone but is not an email address, ipad setup process will not allow me to use current id or change id to primary email address - do I have to have different id for ipad

    It does have to be a verifiable email address though, you can change it here:
    Apple ID support
    http://www.apple.com/support/appleid/

  • Can't delete grayed-out DNS server addresses

    I want to replace two grayed-out DNS server addresses from the Network panel (under the DNS tab in "Advanced…"), to replace them with OpenDNS settings. But they can't be selected/deleted. How do I get around this problem?

    That is correct - those are provided by your router and can not be deleted - you can add Open DNS servers (click the + sign) or log into the router admin page (I recommend this way) and have your router use the Open DNS servers fro everything on your network (this will change the grayed out ones)
    LN

  • How to prevent changing DNS server address

    I work for a public school district. We just purchased our first batch of Win 8.1 PCs, but they are not the Pro version, so there is no gpedit.  I want to prevent students from accessing the TCP/IPv4 Properties dialog box in order to ensure that the
    DNS server address is always obtained automatically.  Can anyone tell me how to do this using regedit, or any other way?  Thanks!

    Easiest way is to assign these students a standard user account (without admin rights).. They cant change any system setting then.. Other than restricting privileges I don't think you have option here since you don't have group policy editor ..
    There could be a possibility to do this using regedit But it is not recommended since there are no any official article for this other than below untested third party article form ehow
    http://www.ehow.com/how_8110801_disable-tcpip-properties-regedit.html
    Besides it could be tedious.. enabling and disabling it.. 

  • How do I get a DNS server address?

    How do I find my DNS Server address?  I intalled my Airport to my new PC and it has a yellow light and while other wireless computers can see the network they cannot to the internet.

    You cannot get a .mac address any longer - it is all now based on mobileme so xxx.me.com is the email addy domain.
    To get one, you need to subscribe to the mobileme service - http://www.apple.com/mobileme/

  • Manually provided DNS server addresses are higher priority than DHCP's

    Disclaimer: Apple does not necessarily endorse any suggestions, solutions, or third-party software products that may be mentioned in the topic below. Apple encourages you to first seek a solution at Apple Support. The following links are provided as is, with no guarantee of the effectiveness or reliability of the information. Apple does not guarantee that these links will be maintained or functional at any given time. Use the information below at your own discretion.
    With the recent revelation of DNS server security issues, many have expressed a desire to use DNS servers they know to be secure rather than the servers specified by their routers via DHCP, which often are those of a particular ISP.
    When you manually enter a DNS server address in Mac OS X Leopard's Network preference pane, the manually entered address(es) appear below any DHCP-provided addresses (which are shown in grey as they are unchangeable), leading one to assume that DHCP-provided addresses always have priority over any a user may specify.
    However, a check of the /etc/resolv.conf file generated by Mac OS X shows that in fact user-provided DNS addresses will supercede any provided by DHCP.
    As an example, if your router promotes itself as a DHCP server, its IP address, say "192.168.0.253," will appear, greyed out, in the Network->Advanced->DNS preferences pane.
    If you then add, say, OpenDNS' addresses of "208.67.222.222" and "208.67.220.220," the preferences window will show:
    192.168.0.253 (greyed out)
    208.67.222.222
    208.67.220.220
    But the generated /etc/resolv.conf will show the order Mac OS X will actually reference the servers is:
    nameserver 208.67.222.222
    nameserver 208.67.220.220
    nameserver 192.168.0.253
    While this is non-intuitive, given how the addresses are displayed in the preference pane, it is exactly the way a user would hope things would work - allowing one to specify DNS servers to be used in lieu of any a router provides, especially handy if the router propagates the address of a DNS server that is having issues, that is untrusted or is simply overloaded or offline.
    Do you want to provide feedback on this User Contributed Tip or contribute your own? If you have achieved Level 2 status, visit the User Tips Library Contributions forum for more information.

    That's very good to KNOW.
    I figured it as such as I have some manual entries for the office and I don't use profiles, so it stays there when I go home.
    I notice a slow-down when office DNS entries are used at home -as one would suspect.
    I do like KNOWING that it's the case though - thanks for the info!
    Scott

  • Why doesn't my airport express router issue proper DNS server address to DHCP clients?

    I have an Airport express router (version 7.6.4).  It was configured to connect to internet via a cable modem, acting as a router with NAT. This means it obtians WAN address from cable modem, and in LAN it assumes IP address 10.0.1.1 as a gateway, and issue IP address to my 4-5 wireless clients (MBA, iPads, PCs) vi DHCP.
    However I recently encounter an issue, that the router no longer issues DNS server address obtained from Cable Modem(206.x.x.x) but instead tell every DHCP client to use router ip address (10.0.1.1) as DNS server. I was pretty sure before Dec 2013 it is issueing (206.x.x.x) to all DHCP clients.
    Apparently now the Airport express is acting as a DNS server or as a DNS cache. This works sporadically and very often result in long DNS look up or DNS look up failure.
    Is this a bug or is it supposed to do so?  Any configuration can turn it off so Airport express will issue Cable modem obtained DNS server to DHCP clients?
    My network otherwise works fine. for some of the Clients (e.g. one MBA) I configured DNS for it mannually and it's internet is working very smoothly.

    But this will be a problem for my ipad and iphone that uses wifi.
    These devices either allow full DHCP. If you need to mannually enter DNS server, you will need to turn entire IP configuration to mannual and that will be a problem for me.

  • Passing DNS server addresses through DHCP?

    I'm setting up NAT & DHCP (both as a DHCP client & DHCP server) on a 2621. Since the DNS server address(es) are received on the router's interface configured as a DHCP client, is there a way to pass these (possibly dynamic) address(es) on the internal network clients? What I see in the DHCP server functionality is that the option specifying what DNS server(s) are passed on to clients is hard coded. If hard coding the option is my only choice, do I have any guarantee that the ISP will always use the same IP address(es) for its DNS servers?
    Any insight would be appreciated.

    Thats exactly what the 'import all' command is for.
    In your DHCP server, if you supply the command 'import all', it will seek the DHCP information that was given to it on the interface that has "ip address dhcp". It will store the information like DNS into your DHCP server, and then send that out to all devices receiving DHCP addresses from your server.

  • Detect "Obtain DNS server address automatically" set

    Can anyone help me with a minor issue?
    I am trying to detect if this setting is set to manual or automatic
    I am currently using this code
    Get-WmiObject -Class Win32_NetworkAdapterConfiguration -Filter "IPEnabled=TRUE" | Select PSComputerName,DNSServerSearchOrder
    The problem is it returns the servers and not the actual setting of automatic vs manual.
    Powershell v2

    Hi JustuslV,
    Optionally, you can retrieve or set a value corresponding to "Obtain DNS server address automatically" by using the two registry entries, DhcpNameServer and NameServer, which you can find at the following registry location:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces
    \{AdapterIdentifier}
    If the value of NameServer is null, the client tries to obtain a DNS server address automatically from the DHCP server.
    Refer to:
    Part 5: Scripting DNS on Clients
    And you can refer to this script to get the related registry value:
    $adapter=Get-WmiObject -Class Win32_NetworkAdapterConfiguration -Filter "IPEnabled=TRUE" | select -ExpandProperty SettingID
    $path='HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces'
    Get-ItemProperty -Path "$path\$adapter" -Name Nameserver|select -ExpandProperty NameServer
    If there is anything else regarding this issue, please feel free to post back.
    Best Regards,
    Anna Wang

  • Two vpngroup vpnadmin dns-server addresses

    Has anyone or does anyone know how to put two vpngroup vpnadmin dns-server addresses on a PIX 515E?  I am trying to set up a second DNS Server and without the command in the PIX my VPN clients cannot authenticate through the PIX on the second DNS Server.  I have tried several times to put the command in but it keeps removing the existing one and replacing it with the one I try to put in.  Any help would be appreciated.
    Randy L Brown

    You can configure both DNS server on the same command as follows:
    vpngroup vpnadmin dns-server
    Hope this helps.

  • HT1529 what is my iMac DNS IP address

    What is my iMac DNS IP Address.  I (think) I need it to get my apple TV to work.  I had it working yesterday and today it says NO.  (I did nothing different, except turned it on!!)  It doesn't recognise that I have authorised my iTunes account (several times).

    You can determine your Mac's IP address by opening Sytem Preferences, selecting Network and then selecting the interface you are using to connect to your home network (either Ethernet or WiFi). As for its DNS IP address, the Mac will not have its own DNS address. This will typically be the IP address of the wireless router, if WiFi is being used, or your ISP.
    For your Apple TV to see the Mac, this will use Bonjour to locate the Mac on the local network. So the important thing is that your Mac and the Apple TV are set to the same IP subnet. This is usually the first three sets of numbers in your IP address, while the last number is known as the network address. For example, a Mac with an IP address of 10.0.1.4 has an IP subnet of 10.0.1 and a network address of 4. For other devices using Bonjour to communicate with this Mac, they also need an IP subnet of 10.0.1 but a different network address to 4.
    The other important IP address setting is the router address, aka gateway. For all devices to communicate with each other on a local network, they must have the same router address, which is the IP address of the wireless router or Ethernet switch.
    Now I don't have an Apple TV so I don't know the network settings menu but I would expect that it is set to DHCP, meaning that it is relying on the router to provide it with an IP address. The theory would then go that you would also set the Mac to DHCP so that the router can allocate a dedicated IP address to the Mac and Apple TV and any other device on your network. If any device is set to manual assignment then this could be your issue. Are you able to confirm what network settings the Mac and Apple TV are using and post back here?

  • New, Single Server - DNS, Web, Wiki, Mail Setup Issues

    I'm having some issues properly setting up 10.7.3 to host internal DNS and external Web, Wiki and Mail.  I'm having issues with the web and wiki hosting.  Since those are the most important right now, I haven't really had a chance to fully test the other features.  I was able to do some testing of the mail and iCal but it was limited.
    Long read below but I thought the specifics would be helpful...
    My goals and configuration are:
    ***GOALS***
    Primary:
    1) Host a public website: example.org and www.example.org
    2) Host a public wiki: main.example.org and www.main.example.org
    3) Host a public mail server: [email protected]
    4) Host a public, group calendar
    4a) Read only to majority - Read/Write to a group
    5) Host a global address book for authenticated users
    Secondary:
    6) Allow anonymous public access to a file share (read only)
    7) Allow authenticated access to the same file share (read/write)
    8) Do as much of this via GUIs as possible.
    ***SETUP AND CONFIGURATION***
    Physical:
    1) Business class Internet (no blocked ports)
    2) A single, public and static IP address
    3) Domain name and public DNS via GoDaddy
    4) Wildcard Cert: *.example.org from GoDaddy
    5) Late 2011 (bought in Jan 2012) MacMini Lion Server (the $1,000 one).
    5a) Upgraded the RAM to 16GB (need for VMware Windows clients)
    5b) Added two USB to Ethernet adapters.
    6) Using a new model AirPort Extreme Base Station (bought w/ the MM) as the main router.
    Initial Configuration:
    7) Setup a Mac Address reservation for the main and two USB Ethernet ports along with the wireless too.
    7a) Main port = 10.0.1.5 / Others are .6, .7 and .10
    8) During the setup, I chose the Host on the Internet (third) option and named my server: main.example.org
    9) After the setup completed, I upgraded the OS & Admin Tool to 10.7.3 from a clean install (on #5 now)
    DNS Config
    10) I used the admin tool to open DNS and change:
    11) "Primary Zone Name" from main.example.org to example.org.
    12) In the "Nameservers:" block, I changed the zone name there but left the nameserver name alone (zone: example.org /// Nameserver Hostname: main.example.org).
    13) The Machine Name and Reverse Zone was left alone.  RZ resolves to main.example.org.  sudo changeip -checkhostname is good.  dig on the example.org and main.example.org are good to go (NOERROR).
    OD Config
    14) From the server app, I clicked Manage/Network Accounts and setup the OD - No issues.
    SSL
    15) From the server app, I created self signed cert, generated a CSR, got a public Cert, then replaced the self-signed with the public one - No issues.
    16) Changed any service using the self-signed cert to the public one - No issues.
    17) Changed the cert in the OD to the public cert from server admin - No issues.
    In order: File Sharing, Mail, AB, iCal, Web, Wiki, Profile Manager, Network Groups, Network Users
    18) File Sharing was setup using the server app
    19) Setup mail using the server app to start it and the server admin app to configure it - No issues there (I think...)
    20) AB - Flipped the switch to on
    21) iCal - Flipped the switch to on - I setup the e-mail address to use after I added the network accounts.
    22) Web - Flipped the switch to on - Default site worked (main.example.org)
    23) Wiki - Flipped the switch to on - Default wiki worked. (main.example.org)
    24) PM - Checked the sign config profiles and enabled the device mgt.  I then flipped the switch to on - Default settings and pages worked.
    ***MY PROBLEMS***
    Website:
    Adding a website for example.org gave me the red dot in the server app.  To fix that, I added a Machine Name record to my primary zone (PZ = example.org Machine Name = example.org).  I first tried using the same 10.0.1.5 IP as the main.example.org and left the reverse mapping alone (still resolved to the NS of main.example.org).
    That gave me the green light in the server app when trying to add the website again.  From there, I changed the "Store Site Files In" to the location of my website files (and confirmed "Everyone" has Read Access in the folder's security settings).  I left the other info alone (all defaults accepted) and clicked done.
    Access to the website works on the server but external access doesn't (Network Error/timed out tcp_error).  Checked the AirPort settings using the AirPort utility (version 5.5.3) and the Port Mapping (under the "Advanced" icon) show serveral services all pointing to 10.0.1.5.  Thinking it could be DNS I tried main.example.org externally and it failed the same way.
    I ran the changeip command (good to go) and dig on example.org and main.example.org and they both resolved to 10.0.1.5 correctly.
    I removed the example.org Machine Record from the zone and it now looks like:
    PZ=example.org / ZONE=example.org / NS=main.example.org
    Machine Record=main.example.org / IP=10.0.1.5
    RM=10.0.1.5 / Resolves=main.example.org
    PLEASE HELP!

    The amount of users (if relevant):
    On site - 1 (Me)
    Off site - 16 (Windows clients - some have iOS devices too)
    Web site traffic - less than 50 regular visits per day (avg of 15) with a peek of ~125 once a month.
    This is for a 501c3 public nonprofit made of all unpaid volunteers (including the officers and directors).  All of us have paying day jobs and I just so happen to be the guy that knows just enough to get myself in trouble here.

Maybe you are looking for

  • Regarding "select into" query and "no data found" exception

    So i have included the following into my procedure: select div_cd into c_div_cd                from division_tab d, emp_tab y                where d.div_name=y.div_text and y.emp_code=d.emp_code; and also an exception exception when no data found --

  • No pdf indexing

    Hi, I'm using CTXSYS.CONTEXT with URL_DATASTORE. All other parameters are left unspecified (defaults). While plain text docs appear properly indexed, pdf are not. They appear unfiltered, the index contains pdf keywords only. I understood that by defa

  • Need help in text variable !!

    experts ! i have asked question earlier about the problem, i was trying all the possible combinations and i just got another way, Can i use Offset settings for Text variable ? my requirement is , i have ofiscper, and there is a text variable created

  • Does anyone have a site i can view?

    hi there, i am currenty using iWeb to publish a site, mainly of pictures. i am most likely going to punlishing via my .mac trial account. does anyone have any sites they've published from iWeb using either a .mac account or uploading to a different h

  • Error message when trying to buy converter

    I´ve trying to buy the PDF converter, but every time the system send me ti "my cart" I receive an error message saying that my location is not correct