Forward DNS Setup lags..
Hi there,
I have a "forward only" DNS server (i think) setup on my
xserve, 10.5.4.
I'm NAT"d behind a firewall (192.168.1.2). The Xserve is on a DMZ.
I'm experiencing odd DNS "lag" when browsing on client machines.
The xserve has its own IP listed as a DNS server.
The client machines DNS list the Xserve (192.168.1.102).
Whenever i add another DNS (ie, directly to the router or our ISP's
DNS servers) it seems to bog down.
I'm talking a consistent 4-5 second delay before loading an un-cached page.
I have the "outbound" port 53 open on the Server firewall.
It shows NO activity.
Here's my DNS setup on the xserve:
I have two A records :
one for the Xserve (FQDN)
one for my exchange server (FQDN)
One Cname for WWW pointing to the windows server.
I'm pretty sure THIS much of my DNS is correct, as
both hostnames resolve forward and reverse
(as well as good ol' changeip being happy :)). Yes,
Kerberos is running :)
Under "Settings",
"Accept recursive queries from the following networks:"
•192.168.1/24
"Forwarder IP Addresses"
192.168.1.2 - my router. that's it.
I put my router here, as browsing seems slower if
i add our DNS servers from the ISP.
When they're in, i run Traceroute, and there is a 100ms delay
from the client TO the xserve, which sends it to the router.
Questions:
Is my "Accept recursive queries" bit setup right?
With just the LAN IP's?
Is having my router listed as a Forwarder IP Address
a good practice?
I arrived at this through trial and error - again, browsing
seems to take less hops the way it's currently setup.
Many thanks in advance.
~p