[Pdns-users] stupid recursor question [SOLVED]

Brian Candler b.candler at pobox.com
Wed Dec 7 20:17:49 UTC 2022

On 07/12/2022 18:47, Curtis Maurand via Pdns-users wrote:
> dig doesn't return an error
> root at sirius:~# dig sirius.xyonet.com
> ; <<>> DiG 9.16.33-Debian <<>> sirius.xyonet.com
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 10323

To be clear: SERVFAIL *is* an explicit error response from the 
recursor.  It means it couldn't contact any of the nameservers for the 
domain you're querying.

And I suspect this would also fail:

root at sirius:~# dig +norec @ sirius.xyonet.com.

Hence the problem is that the nameserver can't be reached on its 
*public* IP from the *private* network.  But as you've found, sending 
the query to the private IP fixes this.  I'm glad you've managed to make 
it work!

