[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [afnog] Red Hat 8.0 as a router



On Fri, Aug 15, 2003 at 12:16:28PM -0700, Daniel Obuobi wrote:
> Please what is the main difference between the
> installing dns to do resolving and one to be an
> authoritative sever. Are they no installed the same
> way?

Kind of, but it is better to configure them differently:

- an authoritative server should have recursion turned off. This prevents it
being used as a cache, minimises CPU load, and ensures that its RAM usage
is minimal.

- a caching server should be configured with recursion on but only answering
queries from your own IP ranges, to prevent it doing work for other people
on the Internet. It needs to have lots of RAM.

- keeping the boxes separate makes scaling *much* easier, and also prevents
problems when domains are transferred (your cache won't be polluted with
stale information)

This is the advice for an ISP environment, and if you are authoritative for
hundreds or thousands of domains it's really important.

OTOH if this is just some little office system, then one box doing both jobs
will be OK, and indeed if you don't have your own domain (or if your
upstream ISP hosts it for you) then you don't need an authoritative
nameserver at all, just a cache.

Cheers,

Brian.
__________________________________________________
This is the Africa Network Operators' Group(AfNOG) 
technical discussion list.
The AfNOG website is: <http://www.afnog.org>