infoblox_nios:dtc
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| infoblox_nios:dtc [2023/08/10 02:04] – [Health Checks] bstafford | infoblox_nios:dtc [2025/08/24 17:02] (current) – [EDNS0] bstafford | ||
|---|---|---|---|
| Line 3: | Line 3: | ||
| The DTC uses a MaxMind database for GeoIP information. The one that comes with NIOS is old. | The DTC uses a MaxMind database for GeoIP information. The one that comes with NIOS is old. | ||
| - | You can [[https:// | + | You can [[https:// |
| When the DTC subscription expires, [[https:// | When the DTC subscription expires, [[https:// | ||
| + | * **Internal & External Applications**: | ||
| + | * **Disaster Recovery**: Automate service restoration for business-critical apps during disasters. | ||
| + | * **Global Datacenter Management**: | ||
| + | * **Hybrid/ | ||
| + | * **View/Zone Consolidations**: | ||
| + | * **Cascade LBDNs for Multi-Tier Scalability**: | ||
| + | * **SRV Record Support**: Gives administrators a way to intelligently direct authentication by non-site-aware Active Directory clients. | ||
| + | |||
| + | ===== Enable/ | ||
| + | You can enabled/ | ||
| + | |||
| + | See [[infoblox: | ||
| ===== Health Checks ===== | ===== Health Checks ===== | ||
| Line 19: | Line 31: | ||
| HTTP/1.1 | HTTP/1.1 | ||
| HOST: www.example.corp</ | HOST: www.example.corp</ | ||
| + | |||
| + | If you need to use HOST, you will probably need to form the config as follows: | ||
| + | < | ||
| + | HTTP/ | ||
| ===== Limits ===== | ===== Limits ===== | ||
| Line 39: | Line 55: | ||
| * Use a naming convention for LBDN’s, and their associated Pools, Servers, and Topology rules.These naming conventions can be used for filtering within the GUI table views (they can be saved) and to identify a Server vs. Pool Topology rule | * Use a naming convention for LBDN’s, and their associated Pools, Servers, and Topology rules.These naming conventions can be used for filtering within the GUI table views (they can be saved) and to identify a Server vs. Pool Topology rule | ||
| + | ===== DNSSEC ===== | ||
| + | Documentation on DNSSEC with DTC is [[https:// | ||
| + | |||
| + | You can have DNSSEC and DTC configurations on the same zone. There are some prerequisites and limitations that you won’t come across with unsigned zones. | ||
| + | * The GM must have DTC license, because it will create signatures for each possible response. | ||
| + | * There cannot be CNAMEs at the zone apex. Sometimes DTC is used for this workaround for BIND’s reluctance to put CNAMEs at the apex. | ||
| + | |||
| + | See the section " | ||
| + | ===== EDNS0 ===== | ||
| + | When using DTC, if you want DTC to consider EDNS0 option, select "When DNS Traffic Control is enabled, direct traffic according to EDNS0 Client Subnet when possible" | ||
| + | |||
| + | DTC doesn' | ||
| + | ===== Healthcheck Palo Alto Networks Panorama ===== | ||
| + | Use DTC to pole both members of a Panorama HA pair to see which is active. Use in " | ||
| + | |||
| + | HTTP request: | ||
| + | < | ||
| + | GET / | ||
| + | Host: panorama.example.com | ||
| + | Connection: | ||
| + | |||
| + | Response Code Check | ||
| + | < | ||
| + | |||
| + | Search for a string in the response content "both the header and body" | ||
| + | |||
| + | Regular expression | ||
| + | < | ||
| + | |||
| + | The content is valid if the regular expression is " | ||
| ===== Logging ===== | ===== Logging ===== | ||
| ==== HTTP Check ==== | ==== HTTP Check ==== | ||
| - | The following is when checking that GET works with specific match in body. | + | |
| + | As per [[https:// | ||
| + | |||
| + | * **DTC load balancing**: | ||
| + | * **DTC health monitors**: Records any changes to the health state of a monitored server | ||
| + | |||
| + | The following | ||
| + | |||
| + | DNS query | ||
| + | * Facility: Daemon | ||
| + | * Level: Info | ||
| + | * Server: named | ||
| + | * Message: request [source: 192.168.11.30# | ||
| + | |||
| + | |||
| + | The following (DTC health monitor log) is when checking that GET works with specific match in body. | ||
| When the web server was broken by updating the page, the following message is generated. | When the web server was broken by updating the page, the following message is generated. | ||
| Line 56: | Line 117: | ||
| * Message: '' | * Message: '' | ||
| * Message: '' | * Message: '' | ||
| + | |||
| + | The following is for a failed ping. NIOS 9.0.6. Facility may be User in older versions. | ||
| + | * Facility: Kern | ||
| + | * Level: Info | ||
| + | * Server: idns_healthd | ||
| + | * Message: '' | ||
| + | |||
| + | * Facility: Kern | ||
| + | * Level: Info | ||
| + | * Server: idns_healthd | ||
| + | * Message: '' | ||
infoblox_nios/dtc.1691633064.txt.gz · Last modified: by bstafford
