1.時(shí)間不一致引起的問(wèn)題現(xiàn)象:更新dns在ns2報(bào)授權(quán)錯(cuò)誤add zoo.eos.grid.sina.com.cn A 10.75.10.10 on NS: 10.75.14.72...OKadd zoo.eos.grid.sina.com.cn A 10.75.10.10 on NS: 10.75.14.214...FAIL, NOTAUTH在ns2上查看named錯(cuò)誤日志查到/var/log/messageJun 7 11:08:23 leto214 named[30231]: client10.75.14.72#36991: request has invalid signature: TSIG update_key:tsig verify failure(BADTIME)原因:發(fā)現(xiàn)報(bào)錯(cuò)是時(shí)間不一致引起進(jìn)一步排查發(fā)現(xiàn)ns1重啟動(dòng)后ntp服務(wù)沒(méi)有運(yùn)行,時(shí)間有問(wèn)題,使用ntp校準(zhǔn)時(shí)間后,問(wèn)題解決。

2.dns的二進(jìn)制日志損壞引起的問(wèn)題:背景:在/var/named/chroot /var/named下有兩個(gè)重要文件:mars.grid.sina.com.cn.zone.internal;mars.grid.sina.com.cn.zone.internal.jnl前一個(gè)文件記錄的是本dns的zone文件,后一個(gè)文件是dns的二進(jìn)制日志?,F(xiàn)象:Notice: parameter and logic check done,now deal DNSNotice: del 10.55.28.45 of s3377i.mars.grid.sina.com.cn on NS:ns1.mars.grid.sina.com.cn succeedError: del 10.55.28.45 ofs3377i.mars.grid.sina.com.cn on NS: ns2.mars.grid.sina.com.cnfailed, SERVFAIL說(shuō)明:更新ns1.mars成功,更新ns2.mars失敗,報(bào)錯(cuò)SERVER FAIL(http://www.process.com/techsupport/multinet/787/44.html)在ns2上查看日志/var/log/message,沒(méi)有任何報(bào)錯(cuò)信息,就是無(wú)法更新。解決:通過(guò)在named下配置文件named.conf中添加如下代碼,打開(kāi)dns的詳細(xì)錯(cuò)誤日志:
logging { channel default_file { file"/var/log/named.log" size 10m; severitydebug; print-timeyes; print-severity yes; print-category yes; }; category default{default_file; };};捕獲到錯(cuò)誤信息,并確認(rèn)jnl損壞。刪除損壞的jnl文件,從ns1上拷貝zone文件覆蓋本地zone文件,確保數(shù)據(jù)一致性,重啟named。
愛(ài)華網(wǎng)本文地址 » http://www.klfzs.com/a/25101014/229608.html
愛(ài)華網(wǎng)



