image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X Server

Reply
 
LinkBack Thread Tools
  #1  
Old August 28th, 2009, 06:48 AM
RoadKingRick's Avatar
Registered User
 
Join Date: May 2009
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
RoadKingRick is on a distinguished road
DNS gone wild

I do not use my XServer for internet connectivity, merely for fileserving in a static IP environment, but the fine folks at Apple insist that the OS is so heavily reliant on DNS, that it MUST be on. So, it is on, and the XServer is the primary DNS address in the NIC settings on the Macs, the actual firewall is the secondary.

About 2 weeks ago, I noticed a LOT of outbound DNS activity from the XServer on port 53 (dns), occasionally reaching over 600 concurrent outbound connections. If I uncheck "Recursive" in the dns services (Xserve 10.4.11) it stops, but my then Macs can't connect to the internet.

Any thoughts?
Reply With Quote
  #2  
Old August 28th, 2009, 10:48 AM
Satcomer's Avatar
In Geostationary Orbit
 
Join Date: Jul 2002
Location: Northern Virginia
Posts: 7,015
Thanks: 34
Thanked 182 Times in 177 Posts
Satcomer is a jewel in the roughSatcomer is a jewel in the roughSatcomer is a jewel in the roughSatcomer is a jewel in the rough
Maybe you would want to use the OpenDNS Mac server settings and setup a free account detailed in this video. You could take some of the lifting off your DNS and get DNS caching and phishing and block sites for free. Plus setup custom pointers as well, just for your server.
__________________
Mac Pro Dual 2.8 Quad (1st gen), 14G Ram, Two DVD-RW Drives, OS X 10.6.2
Mac Book Pro Core 2 Duo 2.16Ghz, SuperDrive, ATI X1600, 2GB RAM, OS X 10.6.2
2TB Time Capsule
32G iPhone 3GS Black
Reply With Quote
  #3  
Old August 28th, 2009, 11:16 AM
RoadKingRick's Avatar
Registered User
 
Join Date: May 2009
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
RoadKingRick is on a distinguished road
but...

I very much appreciate the info, but my firewall (a completely different computer and OS) handles DNS.
The only reason I have DNS enabled on the XServer at all is because Apple insisted it was necessary even for simple file sharing, but I frankly don't see why that should be.
Maybe if on all the individual computer's NIC's I make the firewall the primary DNS and the XServer the secondary?
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


All times are GMT -5. The time now is 03:14 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0 RC1
Copyright 2000-2010 DigitalCrowd, Inc.