Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Lower Reverse DNS TTL
PostPosted: Thu Dec 31, 2009 11:31 am 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
I'm having trouble getting my reverse DNS ACLs working on my server. I set the reverse DNS about 10 hours ago, but it still has not propagated. The problem is that the TTL on reverse DNS is 24 hours. So, I have to wait another 14 hours till I can get my server running. I think this should be set to a more reasonable 1 hour. Also, the TTL should be noted on the reverse DNS page of Linode Manager.


Top
   
 Post subject:
PostPosted: Thu Dec 31, 2009 3:00 pm 
Offline
Senior Member

Joined: Sat Dec 04, 2004 5:36 pm
Posts: 145
The problem is, there are certain key RBLs that will blacklist you if you have a reverse DNS zone positive TTL of less than 12 hours, causing loss of email. (This only applied to reverse zones.)

I don't recall which major RBL it was that was doing this.


Top
   
 Post subject:
PostPosted: Thu Dec 31, 2009 3:46 pm 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
Maybe a compromise would be to make the default reverse DNS have a lower TTL. People running a mail server would set a reverse hostname, right?

I don't have to mention how much I despise admins who use RBLs without reading about them first.


Top
   
 Post subject:
PostPosted: Thu Dec 31, 2009 7:16 pm 
Offline
Senior Member
User avatar

Joined: Mon Dec 10, 2007 4:30 pm
Posts: 341
Website: http://markwalling.org
Or how about a compromise of setting the reverse DNS before remote sites have a chance to hit the "default" host name? Or just waiting the (reasonable) default of 24 hours?


Top
   
 Post subject:
PostPosted: Thu Dec 31, 2009 7:51 pm 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
It's just a bit inconvenient. I have to setup forward DNS, wait my TTL, then setup reverse DNS, wait Linode's update cycle, then I can boot up my server with the IP. There's a bit of waiting in there.

Waiting 24 hours before I can start setting up a new server is not reasonable. Maybe 20 years ago it was. These days, when I click to create a new server, I expect it now, not tomorrow.


Top
   
 Post subject:
PostPosted: Thu Dec 31, 2009 8:30 pm 
Offline
Senior Member
User avatar

Joined: Sat Aug 30, 2008 1:55 pm
Posts: 1739
Location: Rochester, New York
I think the problem is right about here:

Quote:
I'm having trouble getting my reverse DNS ACLs working on my server.


Why not use IP addresses? They don't change very often, and it'll save a number of DNS queries on each connection. Few things, other than e-mail and IRC, truly care about reverse DNS.


Top
   
 Post subject:
PostPosted: Thu Dec 31, 2009 10:42 pm 
Offline
Senior Member

Joined: Sun Aug 02, 2009 1:32 pm
Posts: 222
Website: https://www.barkerjr.net
Location: Connecticut, USA
I guess it's hard to administer based on IP address. If I want see a list of servers that have access to my mysqld, I only get a list of IPs, which mean nothing to me.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group