Нужно что бы когда на сервере с bind не было интернета. Он продолжал резолвить адреса те которые знает, то есть с кэша.
Нужно для редиректа в фаерволе.
Можно увеличить время очистки и даже выключить. cleaning-interval The server will remove expired resource records from the cache every cleaning-interval minutes. The default is 60 minutes. If set to 0, no periodic cleaning will occur.
This interval is effectively obsolete. Previously, the server would remove expired resource records from the cache every cleaning-interval minutes. BIND 9 now manages cache memory in a more sophisticated manner and does not rely on the periodic cleaning any more. Specifying this option therefore has no effect on the server's behavior.
The additional section cache, also called acache, is an internal cache to improve the response performance of BIND 9. When additional section caching is enabled, BIND 9 will cache an internal short-cut to the additional section content for each answer RR. Note that acache is an internal caching mechanism of BIND 9, and is not related to the DNS caching server function.
контрольный
As long as cleaning-interval was made obsolete by BIND9.5, since memory management was changed, is this planned for acache-cleaning-interval, or is there reason not to do so?
The former (but just in case this is not clear to someone: acache is
100% irrelevant to the «cache» we normally use in the DNS terminology.
It's also 100% irrelevant to the recent security issue: it's an
authoritative-server specific feature).
options {
directory "/var/named";
};
zone "." IN {
type hint;
file "caching-example/named.root";
};
zone "localhost" IN {
type master;
file "caching-example/localhost.zone";
allow-update { none; };
};
zone "0.0.127.in-addr.arpa" IN {
type master;
file "caching-example/named.local";
allow-update { none; };
};
убрал только коментарии
BIND 9.9.7-P3 (Extended Support Version)
Однозначно Debian отдельно запиливает. Интернеты говорят, что это отдельная фишка. Проверил на BIND 9.10.3 - нет такого. А на Debian BIND 9.8.4-rpz2+rl005.12-P1 действительно работает.