Oracle RAC - Zone example.net
Oracle RAC Solution · Config document · referenced from DNS server: Knot, Network and DNS plan
noteThe DBID
1234567890 in the record rac-clsopdb-1234567890 is a made-up value of the right shape, not the identifier of a real database.The forward zone of the whole installation. It holds one address record for every name the cluster, the Grid Infrastructure installer and Backup Exec use: the public names, the VIPs, the three addresses of the SCAN, the interconnect, backup and management names, the backup server and the DNS server itself.
| Item | Value |
|---|---|
| Path on the host | /etc/knot/example.net.zone |
| Host | dns1 (10.30.40.13), Debian 8.5, Knot DNS |
| Zone | example.net |
| Serial as built | 2016102609 |
| Applied with | /etc/init.d/knot restart |
| Checked with | dig @10.30.40.13 example.net axfr, 22 records |
The file
$ORIGIN example.net. $TTL 3600 @ SOA dns1.example.net. hostmaster.example.net. ( 2016102609 ; serial 6h ; refresh 1h ; retry 1w ; expire 1d ) ; minimum NS dns1 dns1 A 10.30.40.13 ; Oracle RAC - public IP oradb01 A 10.30.10.11 oradb02 A 10.30.10.12 ; Oracle RAC - virtual IP oradb01-vip A 10.30.10.21 oradb02-vip A 10.30.10.22 ; Oracle RAC - scan IP oradb-scan A 10.30.10.31 oradb-scan A 10.30.10.32 oradb-scan A 10.30.10.33 ; Oracle RAC - interconnect IP oradb01-int A 10.30.20.11 oradb02-int A 10.30.20.12 ; Oracle RAC - symantec backend oradb01-bck A 10.30.30.11 oradb02-bck A 10.30.30.12 ; Oracle RAC - OS/DB management oradb01-mng A 10.30.40.11 oradb02-mng A 10.30.40.12 oradb01-iscsi A 10.30.50.11 ; Oracle RAC - records for Symantec Backup Exec (the Oracle RAC database named "CLSDB", DBID "1234567890") rac-clsopdb-1234567890 A 10.30.30.11 rac-clsopdb-1234567890 A 10.30.30.12 ; mng-backupsrv01 mng-backupsrv01 A 10.30.40.14 mng-backupsrv01-bck A 10.30.30.14
Reading the records
| Records | Used by |
|---|---|
oradb01, oradb02 | Public host names of the nodes, given to the Grid Infrastructure installer as "Public Hostname" |
oradb01-vip, oradb02-vip | Node VIPs, given to the installer as "Virtual Hostname" |
oradb-scan, three records | The SCAN name; one name that resolves to three addresses |
oradb01-int, oradb02-int | Private interconnect, the alias eth3:INT on each node |
oradb01-bck, oradb02-bck | Backup network; the names the Backup Exec agent was installed under |
oradb01-mng, oradb02-mng | Management network |
rac-clsopdb-1234567890, two records | The virtual RAC node of Backup Exec: database name and DBID, pointing at the backup addresses of both nodes |
mng-backupsrv01, mng-backupsrv01-bck | The Backup Exec server in the management and in the backup network |
Three things in the file are not as tidy as they look.
oradb01-iscsistands under the comment "OS/DB management" although10.30.50.11is the iSCSI network, and there is nooradb02-iscsirecord at all. The notes give no iSCSI address for the second node anywhere.- The comment above the Backup Exec records names the database
CLSDB, while the record itself is built from the nameclsopdb. Both names appear in my notes for the same database; see Overview and design. - The
NSrecord and the SOA primary are correct here:dns1is relative to$ORIGIN example.net.anddns1.example.net.ends with a dot. The reverse zone files do not get this right.
Why the virtual node needs two address records, and what Backup Exec does with them, is in Backup Exec server and RAC backup.
Checked against Knot DNS 3.6.0
| As built | Today |
|---|---|
Three address records for oradb-scan, two for the Backup Exec name, taken to be round robin | Knot 1.6 has no record rotation, so the answers always came in the same order. answer-rotation exists since 2.7.3 and is off by default. Oracle's guide still asks for the SCAN addresses to be "configured as round robin addresses" in DNS |
One name server, NS dns1 | RFC 1912 asks for at least two name servers per domain. For a closed internal zone one server answers, but it is a single point of failure |
$TTL 3600 and SOA minimum 1d | The negative-caching time is the smaller of the SOA record's TTL and its last field, here 3600 seconds and not a day |
Serial 2016102609 | Still the recommended form, year, month, day and a two-digit counter |
| Zone file edited by hand, unsigned | Current Knot can sign zones automatically and can generate reverse records from a forward zone; neither existed in 1.6 |
What an Oracle client loses when the SCAN name is answered without rotation I could not verify. Oracle's text says "round robin" and does not say what breaks without it.