LINUXOR.SK ... open source notes ...

Oracle RAC - knot.conf, remotes and zones

category: solutionz · date: 2016-12-31 · updated: 2026-10-02 · author: LALA

Oracle RAC Solution · Config document · referenced from DNS server: Knot

The part of the Knot DNS configuration that I added on dns1: one remote, which is the server itself, and five zones, each with its zone file and with zone transfer allowed to that remote. The notes show only these two blocks; the rest of the file was left as the Debian package delivered it and is marked here with a comment line.

ItemValue
Path on the host/etc/knot/knot.conf
Hostdns1 (10.30.40.13), Debian 8.5
SoftwareKnot DNS from the Debian package knot, installed with apt-get install knot; the notes do not record the version (Debian 8 carried 1.6.0)
Shown herethe added remotes block and the zones added to the zones section
Applied with/etc/init.d/knot restart

The file

nginx
# ... (the packaged knot.conf continues here; the notes do not show it)

# Definition of Knot aliases for IP addresses.
# Declare just one server: the one the "knot" DNS server itself runs on. Allow a zone transfer for "this-server" below.
remotes {
  this-server {
    address 10.30.40.13@53;
  }
}

# ... (the packaged knot.conf continues here; the notes do not show it)

zones {

# The DNS zone "example.net", using the zone file "/etc/knot/example.net.zone" and allowing a zone transfer initiated from the DNS server itself (this-server).
example.net {
    file "/etc/knot/example.net.zone";
    xfr-out this-server;
}

# The reverse DNS zone "10.30.10.in-addr.arpa", using the zone file "/etc/knot/10.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server).
10.30.10.in-addr.arpa {
    file "/etc/knot/10.30.10.in-addr.arpa";
    xfr-out this-server;
}

# The reverse DNS zone "20.30.10.in-addr.arpa", using the zone file "/etc/knot/20.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server).
20.30.10.in-addr.arpa {
    file "/etc/knot/20.30.10.in-addr.arpa";
    xfr-out this-server;
}

# The reverse DNS zone "30.30.10.in-addr.arpa", using the zone file "/etc/knot/30.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server).
30.30.10.in-addr.arpa {
    file "/etc/knot/30.30.10.in-addr.arpa";
    xfr-out this-server;
}

# The reverse DNS zone "40.30.10.in-addr.arpa", using the zone file "/etc/knot/40.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server).
40.30.10.in-addr.arpa {
    file "/etc/knot/40.30.10.in-addr.arpa";
    xfr-out this-server;
}

# ... (the packaged knot.conf continues here; the notes do not show it)

What the lines do

LineMeaning
remotes { this-server { address 10.30.40.13@53; } }Gives the address and port of the DNS server itself a name that the zone blocks can refer to
file "/etc/knot/example.net.zone";The zone file of the zone; every zone has its own file in /etc/knot
xfr-out this-server;Allows a zone transfer of this zone to the named remote, here only to the server's own address

The zone transfer is allowed for one purpose: the tests. With xfr-out this-server a dig @10.30.40.13 <zone> axfr run on dns1 itself prints the whole zone as the server loaded it, which is how the mistakes in the reverse zones became visible. No secondary DNS server exists in the notes, and no other host may transfer the zones.

The five zone files are Config documents of their own.

ZoneZone fileConfig document
example.net/etc/knot/example.net.zoneZone example.net
10.30.10.in-addr.arpa/etc/knot/10.30.10.in-addr.arpaReverse zone, public network
20.30.10.in-addr.arpa/etc/knot/20.30.10.in-addr.arpaReverse zone, interconnect network
30.30.10.in-addr.arpa/etc/knot/30.30.10.in-addr.arpaReverse zone, backup network
40.30.10.in-addr.arpa/etc/knot/40.30.10.in-addr.arpaReverse zone, management network

There is no zone for the iSCSI network 10.30.50.x.

Checked against Knot DNS 3.6.0

Debian 8 carried Knot DNS 1.6.0, so that is most likely what the package installed; the notes do not say. The last 1.6 release was 1.6.8 in August 2016. The current stable branch is 3.6.0 of September 2026, and Debian 13 ships 3.4.6.

As builtToday
Configuration in the 1.x format with blocks in bracesReplaced in Knot 2.0.0 (June 2015) by a YAML text format. No 2.x or 3.x server reads a 1.x file
remotes as a list of servers whose role is decided where they are usedremote: describes outgoing connections only, such as the source of a transfer or the target of a notification
xfr-out this-server; to permit a transferAn acl: rule with action: transfer, matched on address or TSIG key and referenced from the zone's acl
Five zone blocks that repeat the same optionA template: with the identifier default applies to every zone
No converter needed in 2016The converter knot1to2 shipped with 2.0 to 2.4 and was removed in 2.5.0; today the file is rewritten by hand
/etc/init.d/knot restart after every changeknotc reload or knotc zone-reload for changed zone files, knotc conf-check for the configuration; no restart is needed for a zone edit

The meaning of the two statements has not changed, only where they are written: in 1.6 xfr-out named the remotes "permitted to obtain zone's contents via zone transfer", and the transfer to the server's own address worked because the query came from the listed address. Knot DNS downloads and supported versions.

← solutionz