DNS challenges - BuddyNS and others

Status, I am receiving emails and my old DNS server is hacked to point to my MiaB. I have updated my registrar, name.com, and that SHOULD propagate and make MiaB as my nameserver with a couple secondaries. But I am having problems with both secondaries and want to add BuddyNS as a secondary. I have set up my account with them, pointing my domain (htt-consult.com) to MiaB (klovia.htt-consult.com). But the challenge is setting them up as a nameserver using the Custom DNS page.

BuddyNS does not seem to have a “simple” FQDN to put into the nameserver dialog as I do for ns1.mudkips.net & puck.nether.net. Per:

There is a lot to configure for NSD, which is outside the MiaB control.

Thus how do I setup the AXFR for BuddyNS?

I also set up puck.nether.net as a secondary, and it does not seem to be getting zone updates. No response from the email addr of the maintainer. He may have been away for the weekend…

Any guidance on how to troubleshoot transfers with puck is appreciated.

2nd question:

How can I get www.htt-consult.com resolve to a different server? medon.htt-consult.com has been the CNAME for www.htt-consult.com for a lot of years.

For AXFR, see the documentation on the Custom DNS page: “To enable zone transfers to additional servers without listing them as secondary nameservers, prefix a hostname, IP address, or subnet with xfr:, e.g. xfr:10.20.30.40 or xfr:10.0.0.0/8.”
I’m also seeing zone update issues with puck. At the moment I was sitting that one out.

I was hoping for some shortcut for BuddyNS. There are 15 IP addrs to list this way. I will give it a shot.

You mean like this?

axfr:108.61.224.67 axfr:116.203.6.3 axfr:107.191.99.111 axfr:193.109.120.66 axfr:23.27.101.128 axfr:192.184.93.99 axfr:103.25.56.55 axfr:216.73.156.203 axfr:37.143.61.179 axfr:195.20.17.193 axfr:45.77.29.133 axfr:116.203.0.64 axfr:167.88.161.228 axfr:199.195.249.208 axfr:104.244.78.122 axfr:2605:6400:30:fd6e::3 axfr:2605:6400:10:65::3 axfr:2605:6400:20:d5e::3 axfr:2a01:4f8:1c0c:8122::3 axfr:2001:19f0:7001:381::3 axfr:2a10:1fc0:d::ae75:f39a axfr:2a01:a500:2766::5c3f:d10b axfr:2602:fafd:902:51::a axfr:2406:d500:2::de4f:f105 axfr:2604:180:1:92a::3 axfr:2606:fc40:4003:26::a axfr:2a10:1fc0:1::e313:41be axfr:2604:180:2:4cf::3 axfr:2a01:4f8:1c0c:8115::3 axfr:2001:19f0:6400:8642::3

Just copy paste that into the secondary dns field, together with your chosen buddy dns servers.

I am not supporting IPv6. So I was not planning on adding those transfers.

What do you mean on this?

See Setup zone delegation with BuddyNS - BuddyNS Secondary DNS

I am pasting secondary nameservers like this

uz5x6wcwzfbjs8fkmkuchydn9339lf7xbxdmnp038cmyjlgg9sprr2.free.ns.buddyns.com uz56xw8h7fw656bpfv84pctjbl9rbzbqrw4rpzdhtvzyltpjdmx0zq.free.ns.buddyns.com uz588h0rhwuu3cc03gm9uckw0w42cqr459wn1nxrbzhym2wd81zydb.free.ns.buddyns.com uz5154v9zl2nswf05td8yzgtd0jl6mvvjp98ut07ln0ydp2bqh1skn.free.ns.buddyns.com uz5dkwpjfvfwb9rh1qj93mtup0gw65s6j7vqqumch0r9gzlu8qxx39.free.ns.buddyns.com uz5w6sb91zt99b73bznfkvtd0j1snxby06gg4hr0p8uum27n0hf6cd.free.ns.buddyns.com uz52u1wtmumlrx5fwu6nmv22ntcddxcjjw41z8sfd6ur9n7797lrv9.free.ns.buddyns.com

Should I use as you suggest the axfr?

I am using the free ones.

OK. I am beginning to get this.

besides the xfr I add a nameserver.

Yeah, you create one string, starting with the nameservers you selected. It seems like you take a lot of them. Are you sure you can configure that many at name.com (your domain registrar? I’m used to being limited to three or four, five tops. But I’m not using name.com, so what do I know.
I would suggest using all ipv4 addresses with the axfr part of the string. Beforehand, you don´t know which server will be making the request.
The string then becomes:

<buddyns_nameserver_1> <buddyns_nameserver_2> axfr:108.61.224.67 axfr:116.203.6.3 axfr:107.191.99.111 axfr:193.109.120.66 axfr:23.27.101.128 axfr:192.184.93.99 axfr:103.25.56.55 axfr:216.73.156.203 axfr:37.143.61.179 axfr:195.20.17.193 axfr:45.77.29.133 axfr:116.203.0.64 axfr:167.88.161.228 axfr:199.195.249.208 axfr:104.244.78.122

Great! Thanks! Was not aware of this.

My custom nameserver field has:

ns1.mudkips.net puck.nether.net xfr:108.61.224.67 xfr:116.203.6.3 xfr:107.191.99.111 xfr:193.109.120.66 xfr:5.223.55.119 xfr:192.184.93.99 xfr:103.25.56.55 xfr:216.73.156.203 xfr:37.143.61.179 xfr:195.20.17.193 xfr:45.77.29.133 xfr:116.203.0.64 xfr:167.88.161.228 xfr:199.195.249.208 xfr:104.244.78.122 uz588h0rhwuu3cc03gm9uckw0w42cqr459wn1nxrbzhym2wd81zydb.free.ns.buddyns.com uz53c7fwlc89h7jrbxcsnxfwjw8k6jtg56l4yvhm6p2xf496c0xl40.free.ns.buddyns.com

Looks good to me

For your information: mail-in-a-box will also add the nameserver you provide (e.g. puck.nether.net) to the axfr allowed list. Thus it might work anyway, because those axfr ip addresses buddyns mentions are probably translated to the list of dns servers they offer (I did not check). But by following the buddyns advice to allow all those ip addresses for axfr, you can be (more) sure it won´t fail.

BuddyNS is now showing OK on their dashboard. So I think I am good there.

But where is MiaB putting all the xfr information? I can’t find it…

/etc/nsd/nsd.conf.d/zones.conf

1 Like

Check propagation NS

I am pretty much populated around according to that checker.

I am having an internal problem, but it does not feel like DNS, but my internal firewall. I can’t get to my printer subnet. I think I made a change there yesterday… Sigh…

Anyway my outstanding DNS challenge is www.htt-consult.com as I asked at the beginning.

DNS challange as in provisioning the Let’s Encrypt certificate?

Well that eventually…

No. I want www.htt-consult.com NOT to map via an A RR to my MiaB on klovia.htt-consult.com as the default, but rather a CNAME to medon.htt-consult.com

Sorry I lost you there. But good luck.

1 Like

Solved my printer problem by going into the room they are in and seeing the powerstrip plug kicked out. :slight_smile:

But back to www.mydomain.

Hey, it works. You have to set 2 custom records

mydomain A record
and
www.mydomain A record or CNAME record.

well, that went well.

I should probably leave things alone for a couple days and then see what is still not right.

I DON’T like what roundcube has done and don’t see a way to change it. The UI is so wasteful of space. I like how it was back in 1.0 over this 1.6 version.

I DO need to spin up a full local DNS resolver, but that is outside of MiaB. I was/am looking a KaliLinux on one of my Cubieboards, but can’t get the build working, so may end up buying a RPi4 for running unbound.

I put in a custom CNAME for medon as www.htt-consult.com and it is working!