Oracle RAC - Reverse zone, management network
Oracle RAC Solution · Config document · referenced from DNS server: Knot
dns1.example.net without the final dot. Do not copy that line as it is; the effect is described below the file.The reverse zone of the management network 10.30.40.x: the management addresses of the two nodes, and the only reverse zone with an NS record.
| Item | Value |
|---|---|
| Path on the host | /etc/knot/40.30.10.in-addr.arpa |
| Host | dns1 (10.30.40.13), Debian 8.5, Knot DNS |
| Zone | 40.30.10.in-addr.arpa |
| Serial as built | 20161006 |
| Applied with | /etc/init.d/knot restart |
| Checked with | dig @10.30.40.13 40.30.10.in-addr.arpa axfr, 5 records |
The file
$TTL 86400 40.30.10.in-addr.arpa. IN SOA dns1.example.net hostmaster.example.net. ( 20161006 ; serial 4h ; slave refresh 2h ; slave retry interval 2w ; slave data expiration 1h ) ; maximum caching time when lookups fail ; 40.30.10.in-addr.arpa. IN NS dns1.example.net. 11.40.30.10.in-addr.arpa. IN PTR oradb01-mng.example.net. 12.40.30.10.in-addr.arpa. IN PTR oradb02-mng.example.net.
The mistake in the SOA record
The owner names in this file are all written in full and end with a dot, so the file needs no $ORIGIN line. The first name after SOA does not end with a dot. A name without the final dot is relative, and the server appended the zone name to it. The zone transfer shows what was loaded: the SOA primary of this zone is dns1.example.net.40.30.10.in-addr.arpa.
The primary server of the zone is therefore a name that does not exist. Nothing in the installation depended on that field: no secondary server and no dynamic update is in the notes, and the PTR records came out as written. The mailbox name hostmaster.example.net. has its dot and came out right.
What else to read in it
- This is the only reverse zone file with an
NSrecord, and the record is written correctly, with the final dot. The other three files have none: public, interconnect, backup. - The DNS server
dns1(10.30.40.13) and the backup servermng-backupsrv01(10.30.40.14) have their addresses in this network and their names in the forward zone, but no reverse record here.
Checked against Knot DNS 3.6.0
| As built | Today |
|---|---|
One NS record | Present and correct. RFC 1912 asks for at least two name servers per domain |
SOA primary dns1.example.net without the final dot | RFC 1035 calls a name that does not end in a dot relative and completes it with the origin. Knot 3.6.0 produces exactly the same result as in 2016. RFC 1912: "Double check, triple check, those trailing dots, especially in in-addr.arpa zone files, where they are needed the most" |
No $ORIGIN line | Knot takes the zone name from its configuration as the initial origin, in 1.6 and today |
$TTL 86400 and the last SOA field 1h | The negative-caching time is the smaller of the two, 3600 seconds; the comment in the file describes that field correctly |
| Eight-digit serial | A valid, merely smaller number. The recommended form has ten digits, and switching to it later is an increase, so it is safe |
| PTR records written by hand | Knot can generate reverse records from a forward zone since 3.3.0 |
Both defects of the reverse zones are of the kind a zone checker finds before the server is restarted. kzonecheck appeared in Knot 2.3.0; the 1.6 server had knotc checkzone, which the notes do not use.