• Bind IPV6 issue

    From Duleep Thilakarathne@dchandimal@gmail.com to bind-users on Thu Jul 9 14:31:40 2020
    From Newsgroup: comp.protocols.dns.bind

    --00000000000058e0af05a9fe7a3f
    Content-Type: text/plain; charset="UTF-8"

    Hi,

    I have configured bind with IPV6 support enabled. However bind does not
    listen to IPV6 address. Any particular reason.is there any place to enable
    IPV6 support other than named.conf.

    Version : BIND 9.11.4-P1 (Extended Support Version)


    in named.conf file

    listen-on-v6 { any; };


    regards
    DT

    --00000000000058e0af05a9fe7a3f
    Content-Type: text/html; charset="UTF-8"
    Content-Transfer-Encoding: quoted-printable

    <div dir=3D"ltr">Hi,<div><br><div>I have configured bind with IPV6 support = enabled. However bind does not listen to IPV6 address. Any particular=C2=A0=
    <a href=3D"http://reason.is">reason.is</a> there any place to enable IPV6 s= upport other than named.conf.</div><div><br></div><div>Version : BIND 9.11.= 4-P1 (Extended Support Version)<br></div><div><br></div><div><br></div><div= >in named.conf file</div><div><br></div><div>listen-on-v6 { any; };<br></di= v><div><br></div><div><br></div><div>regards</div><div>DT</div></div></div>

    --00000000000058e0af05a9fe7a3f--
    --- Synchronet 3.18a-Linux NewsLink 1.113
  • From Anand Buddhdev@anandb@ripe.net to Duleep Thilakarathne on Thu Jul 9 11:28:18 2020
    From Newsgroup: comp.protocols.dns.bind

    On 09/07/2020 11:01, Duleep Thilakarathne wrote:

    Hi Duleep,

    I have configured bind with IPV6 support enabled. However bind does not listen to IPV6 address. Any particular reason.is there any place to enable IPV6 support other than named.conf.

    Version : BIND 9.11.4-P1 (Extended Support Version)

    in named.conf file

    listen-on-v6 { any; };

    This should work. But how do you know that BIND does not listen on IPv6 addresses? Did you check using "ss -lunp" or "netstat -upan"?

    Regards,
    Anand
    --- Synchronet 3.18a-Linux NewsLink 1.113
  • From Nyamkhand Buluukhuu@nyamkhand@mobicom.mn to bind-users@lists.isc.org on Thu Jul 9 17:42:34 2020
    From Newsgroup: comp.protocols.dns.bind

    --_000_HK2PR06MB35238B7F65BD585EC8E7B153CC640HK2PR06MB3523apcp_
    Content-Type: text/plain; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable

    Hello,

    listen-on-v6 port 53 {};

    You can try like above.
    then after restarting named, check result from 'netstart -ltnp' command to = see if v6 address is listening.

    Have a nice day :)
    BR, NYAMKHAND Buluukhuu



    ________________________________
    From: bind-users <bind-users-bounces@lists.isc.org> on behalf of Duleep Thi= lakarathne <dchandimal@gmail.com>
    Sent: Thursday, July 9, 2020 5:01 PM
    To: bind-users@lists.isc.org <bind-users@lists.isc.org>
    Subject: Bind IPV6 issue

    Hi,

    I have configured bind with IPV6 support enabled. However bind does not lis= ten to IPV6 address. Any particular reason.is<https://protect2.fireeye.com/= v1/url?k=3Db96f3e33-e7f7acf6-b96807ec-86982a5fc978-1032b724f3f312c6&q=3D1&e= =3D17bbfe92-8468-4378-8c71-444c92a61cb8&u=3Dhttp%3A%2F%2Freason.is%2F> ther=
    e any place to enable IPV6 support other than named.conf.

    Version : BIND 9.11.4-P1 (Extended Support Version)


    in named.conf file

    listen-on-v6 { any; };


    regards
    DT

    --_000_HK2PR06MB35238B7F65BD585EC8E7B153CC640HK2PR06MB3523apcp_
    Content-Type: text/html; charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable

    <html>
    <head>
    <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=

    <style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo= ttom:0;} </style>
    </head>
    <body dir=3D"ltr">
    <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
    : 12pt; color: rgb(0, 0, 0);">
    Hello,</div>
    <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
    : 12pt; color: rgb(0, 0, 0);">

    </div>
    <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
    : 12pt; color: rgb(0, 0, 0);">
    listen-on-v6 port 53 {};<br>
    </div>
    <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
    : 12pt; color: rgb(0, 0, 0);">

    </div>
    <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
    : 12pt; color: rgb(0, 0, 0);">
    You can try like above.</div>
    <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
    : 12pt; color: rgb(0, 0, 0);">
    then after restarting named, check result from 'netstart -ltnp' command to = see if v6 address is listening.</div>
    <div>
    <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
    : 12pt; color: rgb(0, 0, 0);">

    </div>
    <div id=3D"Signature">
    <div>
    <div></div>
    <div></div>
    <div></div>
    <div></div>
    <div id=3D"divtagdefaultwrapper" dir=3D"ltr" style=3D"font-size:12pt; color= :#000000; font-family:Calibri,Helvetica,sans-serif">
    <p style=3D"margin-top:0px; margin-bottom:0px; margin-top:0; margin-bottom:= 0"></p>
    <p class=3D"MsoNormal" style=3D"margin-top:0px; margin-bottom:0px"><a name= =3D"_MailAutoSig" id=3D"LPlnk292281" class=3D"OWAAutoLink" style=3D"font-fa= mily:Calibri,Helvetica,sans-serif,EmojiFont,&quot;Apple Color Emoji&quot;,&= quot;Segoe UI Emoji&quot;,NotoColorEmoji,&quot;Segoe UI Symbol&quot;,&quot;= Android Emoji&quot;,EmojiSymbols; font-size:16px"><span style=3D"font-size:= 10pt; font-family:Tahoma,sans-serif"><i style=3D"">Have
    a nice day :)</i></span></a><b></b><br>

    <p class=3D"MsoNormal" style=3D"margin-top:0px; margin-bottom:0px"><a name= =3D"_MailAutoSig"><b><span style=3D"font-size:10.0pt; font-family:&quot;Tah= oma&quot;,&quot;sans-serif&quot;; color:black">BR, NYAMKHAND Buluukhuu</spa= n></b></a><span style=3D""><span style=3D""></span></span></p>
    <p class=3D"MsoNormal" style=3D"margin-top:0px; margin-bottom:0px"><span st= yle=3D""><b><span style=3D"color:#1F497D">&nbsp;</span></b></span></p>

    <p style=3D"margin-top:0px; margin-bottom:0px"></p>
    </div>
    </div>
    </div>
    </div>
    <div id=3D"appendonsend"></div>
    <hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
    <div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st= yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> bind-users &lt;bind-u= sers-bounces@lists.isc.org&gt; on behalf of Duleep Thilakarathne &lt;dchand= imal@gmail.com&gt;<br>
    <b>Sent:</b> Thursday, July 9, 2020 5:01 PM<br>
    <b>To:</b> bind-users@lists.isc.org &lt;bind-users@lists.isc.org&gt;<br> <b>Subject:</b> Bind IPV6 issue</font>
    <div>&nbsp;</div>
    </div>
    <div>
    <div dir=3D"ltr">Hi,
    <div><br>
    <div>I have configured bind with IPV6 support enabled. However bind does no=
    t listen to IPV6 address. Any particular&nbsp;<a href=3D"https://protect2.f= ireeye.com/v1/url?k=3Db96f3e33-e7f7acf6-b96807ec-86982a5fc978-1032b724f3f31= 2c6&amp;q=3D1&amp;e=3D17bbfe92-8468-4378-8c71-444c92a61cb8&amp;u=3Dhttp%3A%= 2F%2Freason.is%2F">reason.is</a>
    there any place to enable IPV6 support other than named.conf.</div>
    <div><br>
    </div>
    <div>Version : BIND 9.11.4-P1 (Extended Support Version)<br>
    </div>
    <div><br>
    </div>
    <div><br>
    </div>
    <div>in named.conf file</div>
    <div><br>
    </div>
    <div>listen-on-v6 { any; };<br>
    </div>
    <div><br>
    </div>
    <div><br>
    </div>
    <div>regards</div>
    <div>DT</div>
    </div>
    </div>
    </div>
    </body>
    </html>

    --_000_HK2PR06MB35238B7F65BD585EC8E7B153CC640HK2PR06MB3523apcp_--
    --- Synchronet 3.18a-Linux NewsLink 1.113
  • From Duleep Thilakarathne@dchandimal@gmail.com to Anand Buddhdev on Thu Jul 9 16:26:25 2020
    From Newsgroup: comp.protocols.dns.bind

    --00000000000017169c05aa0014cd
    Content-Type: text/plain; charset="UTF-8"

    Hi Anand,

    Yes netstat -upan only shows only ipv4 address listen :53. But sever
    listens for ipv6 SSH port. So i can confirm IPV6 working fine in server.
    But not for udp port 53.

    Regards
    DT

    On Thu, 9 Jul 2020, 14:58 Anand Buddhdev, <anandb@ripe.net> wrote:

    On 09/07/2020 11:01, Duleep Thilakarathne wrote:

    Hi Duleep,

    I have configured bind with IPV6 support enabled. However bind does not listen to IPV6 address. Any particular reason.is there any place to
    enable
    IPV6 support other than named.conf.

    Version : BIND 9.11.4-P1 (Extended Support Version)

    in named.conf file

    listen-on-v6 { any; };

    This should work. But how do you know that BIND does not listen on IPv6 addresses? Did you check using "ss -lunp" or "netstat -upan"?

    Regards,
    Anand


    --00000000000017169c05aa0014cd
    Content-Type: text/html; charset="UTF-8"
    Content-Transfer-Encoding: quoted-printable

    <div dir=3D"auto">Hi Anand,<div dir=3D"auto"><br></div><div dir=3D"auto">Ye=
    s netstat -upan only shows only ipv4 address listen :53. But sever listens = for ipv6 SSH port. So i can confirm IPV6 working fine in server. But not fo=
    r udp port 53.</div><div dir=3D"auto"><br></div><div dir=3D"auto">Regards= =C2=A0</div><div dir=3D"auto">DT</div></div><br><div class=3D"gmail_quote">= <div dir=3D"ltr" class=3D"gmail_attr">On Thu, 9 Jul 2020, 14:58 Anand Buddh= dev, &lt;<a href=3D"mailto:anandb@ripe.net">anandb@ripe.net</a>&gt; wrote:<= br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;borde= r-left:1px #ccc solid;padding-left:1ex">On 09/07/2020 11:01, Duleep Thilaka= rathne wrote:<br>

    Hi Duleep,<br>

    &gt; I have configured bind with IPV6 support enabled. However bind does no= t<br>
    &gt; listen to IPV6 address. Any particular <a href=3D"http://reason.is" re= l=3D"noreferrer noreferrer" target=3D"_blank">reason.is</a> there any place=
    to enable<br>
    &gt; IPV6 support other than named.conf.<br>
    &gt; <br>
    &gt; Version : BIND 9.11.4-P1 (Extended Support Version)<br>
    &gt; <br>
    &gt; in named.conf file<br>
    &gt; <br>
    &gt; listen-on-v6 { any; };<br>

    This should work. But how do you know that BIND does not listen on IPv6 <br=

    addresses? Did you check using &quot;ss -lunp&quot; or &quot;netstat -upan&= quot;?<br>

    Regards,<br>
    Anand<br>
    </blockquote></div>

    --00000000000017169c05aa0014cd--
    --- Synchronet 3.18a-Linux NewsLink 1.113
  • From Anand Buddhdev@anandb@ripe.net to Duleep Thilakarathne on Thu Jul 9 13:51:34 2020
    From Newsgroup: comp.protocols.dns.bind

    On 09/07/2020 12:56, Duleep Thilakarathne wrote:

    Hi Duleep,

    After starting BIND, can you examine its log entries? It should print
    all the addresses it is binding to, eg:

    09-Jul-2020 13:50:57.674 listening on IPv4 interface lo0, 127.0.0.1#53 09-Jul-2020 13:50:57.676 IPv6 socket API is incomplete; explicitly
    binding to each IPv6 address separately
    09-Jul-2020 13:50:57.676 listening on IPv6 interface lo0, ::1#53
    09-Jul-2020 13:50:57.677 listening on IPv6 interface lo0, fe80::1%1#53 09-Jul-2020 13:50:57.678 listening on IPv6 interface en0, fe80::46f:4f61:8541:6b2f%4#53
    09-Jul-2020 13:50:57.679 listening on IPv4 interface en0, 192.168.178.20#53 09-Jul-2020 13:50:57.680 listening on IPv6 interface en0, 2001:1c04:2a11:7d00:1cb9:6e7e:d4b3:ae1b#53
    09-Jul-2020 13:50:57.681 listening on IPv6 interface en0, 2001:1c04:2a11:7d00:61ed:2e3:3afc:b116#53

    Hi Anand,

    Yes netstat -upan only shows only ipv4 address listen :53. But sever
    listens for ipv6 SSH port. So i can confirm IPV6 working fine in server.
    But not for udp port 53.
    --- Synchronet 3.18a-Linux NewsLink 1.113
  • From Hrant Dadivanyan@hrant@dadivanyan.com to bind-users on Thu Jul 9 18:06:32 2020
    From Newsgroup: comp.protocols.dns.bind

    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --1mTIpzRH0Qnxsa0mbuhS3JjmsJxunPX1X
    Content-Type: multipart/mixed; boundary="ps5nDQGZ6hcpoHD5sqo0Gi0WShtVvOMwk"

    --ps5nDQGZ6hcpoHD5sqo0Gi0WShtVvOMwk
    Content-Type: text/plain; charset=utf-8
    Content-Language: en-US
    Content-Transfer-Encoding: quoted-printable


    Hi Duleep,

    Any process running as non-root user can't bind to a port lower than
    1024 (53 in your case), so if you change process uid on start (named -u)
    then stop the named process and start anew.

    Thank you,
    Hrant

    On 2020-07-09 14:56, Duleep Thilakarathne wrote:
    Hi Anand,
    =20
    Yes netstat -upan only shows only ipv4 address listen :53. But sever
    listens for ipv6 SSH port. So i can confirm IPV6 working fine in server=
    =2E
    But not for udp port 53.
    =20
    Regards=C2=A0
    DT
    =20
    On Thu, 9 Jul 2020, 14:58 Anand Buddhdev, <anandb@ripe.net <mailto:anandb@ripe.net>> wrote:
    =20
    On 09/07/2020 11:01, Duleep Thilakarathne wrote:
    =20
    Hi Duleep,
    =20
    > I have configured bind with IPV6 support enabled. However bind
    does not
    > listen to IPV6 address. Any particular reason.is
    <http://reason.is> there any place to enable
    > IPV6 support other than named.conf.
    >
    > Version : BIND 9.11.4-P1 (Extended Support Version)
    >
    > in named.conf file
    >
    > listen-on-v6 { any; };
    =20
    This should work. But how do you know that BIND does not listen on =
    IPv6
    addresses? Did you check using "ss -lunp" or "netstat -upan"?
    =20
    Regards,
    Anand
    =20
    =20
    _______________________________________________
    Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsub=
    scribe from this list
    =20
    ISC funds the development of this software with paid support subscripti=
    ons. Contact us at https://www.isc.org/contact/ for more information.
    =20
    =20
    bind-users mailing list
    bind-users@lists.isc.org
    https://lists.isc.org/mailman/listinfo/bind-users
    =20


    --ps5nDQGZ6hcpoHD5sqo0Gi0WShtVvOMwk--

    --1mTIpzRH0Qnxsa0mbuhS3JjmsJxunPX1X
    Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature
    Content-Disposition: attachment; filename="signature.asc"

    -----BEGIN PGP SIGNATURE-----
    Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/

    iQEzBAEBCAAdFiEEPbz+l3tnoK718ci3h/fmw7c/bD0FAl8HJGgACgkQh/fmw7c/ bD344Qf/dVNilE8SY7eRqh4sGximY6lAGhfczaLQn5gBbfDH+mnKJ9eEMlkeJoSP j2LlK2Fevi0m+v4a/tkd/eG9aWIBeiZur6moAbz+p74Lr8KR73JvVA9y6MV1ZOdK lWXPzMb8D12VI6wWZu25vETBe3XzAzAmtW6a0cbFSSj9/jAzbn/JfCEr2tmHUe9x hPOnzTrWR44g2KnM68m+6KxLFLapcRmgFSvxScxV/3jJtUjkqaeSlk+BsTyM0J5S RJncFpZxcjBiwL7PHX+mw5iD7KAIMJALk+GQAhINdMVWi6Bq2sSqitAUDlIQCrn9 9SBsdCePNtNDPzTCkgx9KIJNvr+oDQ==
    =IQYa
    -----END PGP SIGNATURE-----

    --1mTIpzRH0Qnxsa0mbuhS3JjmsJxunPX1X--
    --- Synchronet 3.18a-Linux NewsLink 1.113