Too many DNS requests
Hi, have three Xserves running 10.4.11. Just started to plan the migration to 10.6 Server.
Go figure, after years of trouble free service our main file server, Xserve1 has crashed/froze three times in the last week.
It looks like the DNS service is getting hit with a massive amount of requests and it eventually bogs down the server? A reboot gets things going just fine again but after 3 hours or so, the requests start up.
The Xserve2 which is the master DNS and all our client computers are pointed to, it appears to have "some" of the same requests but on a much smaller scale. It has not crashed or froze yet.
Here is a small snippet of the named.log:
27-Mar-2012 02:14:19.746 host unreachable resolving 'zb.akadns.org/A/IN': 2001:500:48::1#53
27-Mar-2012 02:14:19.746 host unreachable resolving 'zb.akadns.org/AAAA/IN': 2001:500:48::1#53
27-Mar-2012 02:14:19.746 host unreachable resolving 'zb.akadns.org/A/IN': 2001:500:f::1#53
27-Mar-2012 02:14:19.746 host unreachable resolving 'zb.akadns.org/AAAA/IN': 2001:500:f::1#53
27-Mar-2012 02:14:19.746 host unreachable resolving 'zc.akadns.org/A/IN': 2001:500:48::1#53
Now I'll explain the server setup:
Xserve1 - AFP services, WIndows services, Open Directory Master, DNS
Xserve2 - AFP services, WIndows services, Open Directory Replica, DNS Master
Xserve3 - AFP services, WIndows services, Open Directory Replica, DNS
Internal NAT network behind a firewall. None of these servers have any mapping to the outside. The only way to login to the servers is to be on the internal network or connect from the outside via VPN. The VPN is a seperate box.
Since Xserve1 is not the Master DNS I just turned the DNS service off for now.
Any help would be appreciated, I'm not a unix or DNS expert but do understand the basics. What I am thinking is that an internal Mac or PC is the computer making the requests.
Is there a way to trace where these requests are coming from?
Is there another log file that has the past requests and what IP they came from?
Thank you for any help you can give. This is frustrating because we thought we were locked down fairly well.
Mike