ehowton: (Sun Logo)

# cat /etc/hosts | grep backendNAS
192.168.0.3

# for x in {4..62} ; do echo "192.168.0.$x backendNAS" >> /etc/roundrobin_nas
# chmod 644 /etc/roundrobin_nas

# cat /etc/dnsmasq.conf | grep addn-hosts
addn-hosts=/etc/roundrobin_nas

# systemctl restart dnsmasq

# nslookup backendNAS

Name: backendNAS
IP: 192.168.1.3

Name: backendNAS
IP: 192.168.1.4

Name: backendNAS
IP: 192.168.1.5

...

Name: backendNAS
IP: 192.168.1.60

Name: backendNAS
IP: 192.168.1.61

Name: backendNAS
IP: 192.168.1.62

◾ Tags:
ehowton: (Default)
My first dns server (secondary host) was a shining beacon of hope, and joy. My second dns server (primary host) was hot garbage. Yes, it worked, but only because it relied completely upon the secondary host. Which was on microsuse. Which was the host I shut down and gave to Dorian.

All hell broke loose.

Eventually, I was able to figure out why the primary dns server was hot garbage, and have shown it another way - a path towards righteousness. A holy path.

Fast, efficient DNS server setup:

DO NOT include the IP of dnsserver itself in its own resolv.conf
DO INCLUDE the gateway IP in the resolv.conf as the last entry

ONLY uncomment/add the following lines to dnsmasq.conf:

domain-needed
bogus-priv
cache-size=300
log-facility=/var/log/dnsmasq.log
conf-dir=/etc/dnsmasq.d/,*.conf

ADD/CONFIRM /etc/dnsmasq.d/trust-anchors.conf
# The root DNSSEC trust anchor, valid as at 11/01/2019

# Note that this is a DS record (ie a hash of the root Zone Signing Key) 
# If was downloaded from https://data.iana.org/root-anchors/root-anchors.xml

trust-anchor=.,20326,8,2,E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D
◾ Tags:
ehowton: (Default)
When:
dnsmasq[454824]: dnsmasq: cannot open log /var/log/dnsmasq.log: Permission denied

Do:
ausearch -c 'dnsmasq' --raw | audit2allow -M my-dnsmasq
semodule -X 300 -i my-dnsmasq.pp
systemctl start dnsmasq


● dnsmasq.service - DNS caching server.
   Loaded: loaded (/usr/lib/systemd/system/dnsmasq.service; enabled; vendor preset: disabled)
   Active: failed (Result: exit-code) since Wed 2022-01-19 10:06:14 CST; 5min ago
  Process: 454824 ExecStart=/usr/sbin/dnsmasq -k (code=exited, status=3)
 Main PID: 454824 (code=exited, status=3)

Jan 19 10:06:14 bkpsrv systemd[1]: Started DNS caching server..
Jan 19 10:06:14 bkpsrv dnsmasq[454824]: dnsmasq: cannot open log /var/log/dnsmasq.log: Permission denied
Jan 19 10:06:14 bkpsrv dnsmasq[454824]: cannot open log /var/log/dnsmasq.log: Permission denied
Jan 19 10:06:14 bkpsrv dnsmasq[454824]: FAILED to start up
Jan 19 10:06:14 bkpsrv systemd[1]: dnsmasq.service: Main process exited, code=exited, status=3/NOTIMPLEMENTED
Jan 19 10:06:14 bkpsrv systemd[1]: dnsmasq.service: Failed with result 'exit-code'.
[root@bkpsrv log]# systemctl start dnsmasq
[root@bkpsrv log]# systemctl status dnsmasq
 dnsmasq.service - DNS caching server.
   Loaded: loaded (/usr/lib/systemd/system/dnsmasq.service; enabled; vendor preset: disabled)
   Active: active (running) since Wed 2022-01-19 10:12:14 CST; 1s ago
 Main PID: 454964 (dnsmasq)
   Memory: 916.0K
   CGroup: /system.slice/dnsmasq.service
           └─454964 /usr/sbin/dnsmasq -k

Jan 19 10:12:14 bkpsrv systemd[1]: Started DNS caching server..
◾ Tags:
ehowton: (Default)
Windows users are retarded:

So there was some domain-swapping going on this weekend, and some boxes apparently cached DNS. This one guy calls me, "The samba share on box1 is missing. The share name is 'samba_share' and it's not there. I logged into the box and couldn't see it."

So I take a peek at the smb.conf file. Yes, the name 'samba_share' is mapped to /filesystem/subdirectory. I explain that we could have named the share, 'ignorant_user' but that didn't mean that the physical directory would actually be visible on the box. He tells me, "Well, honestly, I can't connect to box1 either."

I asked him, "You do understand that's a completely different problem altogether don't you?" He admitted that he did. So I log on to, yes, a windows 'server' (I hate using the term server to describe a windows box.) and can map instantly to said share using IP. I tell the customer this. "Well, you've crippled me, but I suppose I could do that to sneak a few jobs in."

"CRIPPLE YOU?" I exclaim, "I've just freed you! You are no longer bound by name resolution! You can now work more quickly and more efficiently. I've enabled you!"

So he says, "Well, I'll try this....slash slash, box1..."

"NO!" I interrupt - use IP.

"I will, I'm just double-checking that the name won't work."

"That's the reason you called me, is it not?"

*sigh*


My new favorite cat, 'Q':

SomeBritInMass (9:36:45 AM): Q's a nice looking cat. Q from Star Trek?
EricHowton (11:05:14 AM): Q has six toes on each foot
EricHowton (11:05:37 AM): He can turn doorknobs and sip a mug of coffee.
SomeBritInMass (11:09:03 AM): what a cat.
EricHowton (11:12:45 AM): The only thing he can't do is read the morning paper.


The Higgliosaurus Corner:
No HIGGS! news today.


Oregon is Beautiful!
My favorite picture Dan took of Oregon while he was there:

The full size photograph of this can be found on his server here:
Dan's Trip to Oregon, Picture 0134

Tony:
Not that I'm conceding our earlier disagreement concerning your interpretation of the reason for using SWAT, but I did relent and just work over the sonofabitch by hand in the smb.conf. It's just easier that way sometimes.

I'm homeless. What a drag. Now I just...walk the earth, like Kane in Kung-Fu. I spend my nights in the following shelters:
1.) ADC
2.) Tony's
3.) David's
4.) My folks
5.) Wichita, Kansas
Now that's just pathetic!

A&E
Watched a John Water's film last night, "Cecil B. Demented." Pretty good if you're into that sort of thing.

"A bride without a head!"
"A wolf without a foot!"

Sung to the tune of "Dancing Queen" by ABBA:
Danzigfried, young and sweet, only 23.....

The music of the day comes supplied by: My mother's car! Since mine is in the shop.

June 2025

S M T W T F S
1 2 3 4 5 6 7
8 9 1011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Expand Cut Tags

No cut tags