[Xymon] What does the 'dns' test do?
john.horne at plymouth.ac.uk
Tue Mar 12 16:23:46 CET 2019
On Tue, 2019-03-12 at 13:57 +0000, SebA wrote:
> I don't really understand why you would be negating the dns test on the
> server, rather than just removing it altogether. You will be slowing down
> xymonnet if you have tests that are getting blocked by firewalls / iptables.
> If you're interested in a test that checks iptables is running, I made a
> simple extension script I might be able to share.
The check is to ensure that the local (client) DNS service is not 'open'. That
is, that it will not resolve queries from external sources. (And hence prevents
amplification attacks.) We run a separate client DNS test to ensure that local
resolution is working, and, of course, a 'proc' check that 'named' is running.
The 'dns' test/ICMP problem has only just appeared when we moved the monitoring
server. But without knowing what it was that the test was trying to resolve
made it a bit difficult to diagnose.
John Horne | Senior Operations Analyst | Technology and Information Services
University of Plymouth | Drake Circus | Plymouth | Devon | PL4 8AA | UK
This email and any files with it are confidential and intended solely for the use of the recipient to whom it is addressed. If you are not the intended recipient then copying, distribution or other use of the information contained is strictly prohibited and you should not rely on it. If you have received this email in error please let the sender know immediately and delete it from your system(s). Internet emails are not necessarily secure. While we take every care, University of Plymouth accepts no responsibility for viruses and it is your responsibility to scan emails and their attachments. University of Plymouth does not accept responsibility for any changes made after it was sent. Nothing in this email or its attachments constitutes an order for goods or services unless accompanied by an official order form.
More information about the Xymon