10.9 A Nonrecursive Name ServerBy default, BIND resolvers send recursive queries, and BIND name servers do the work required to answer recursive queries. (If you don't remember how recursion works, look in Chapter 2, How Does DNS Work? .) In the process of finding the answer to recursive queries, the name server builds up a cache of nonauthoritative information about other domains. In some circumstances, it is undesirable for name servers to do the extra work required to answer a recursive query or to build up a cache of data. The root name servers are an example of one of these circumstances. The root name servers are so busy that they should not be spending the extra effort to recursively find the answer to a request. Instead, they send a response based only on the authoritative data they have. The response may contain the answer, but it is more likely that the response contains a referral to other name servers. And since the root servers do not support recursive queries, they do not build up a cache of nonauthoritative data, which is good because their cache would be huge.[2]
You can induce BIND to run as a nonrecursive name server with the following conf file statement: options { recursion no; }; On a BIND 4.9 server, that's the directive: options no-recursion Now the server will respond to recursive queries as though they were nonrecursive. In conjunction with recursion no , there is one more configuration option necessary if you want to stop your server from building a cache: options { fetch-glue no; }; Or, on BIND 4.9: options no-fetch-glue This stops the server from fetching missing glue when constructing the additional data section of a response. If you choose to make one of your servers nonrecursive, do not list this name server in any host's resolv.conf file. While you can make your name server nonrecursive, there is no corresponding option to make your resolver work with a nonrecursive name server.[3]
You can list a nonrecursive name server as one of the servers authoritative for your zone data (i.e., you can tell a parent name server to refer queries about your zone to this server). This works because name servers send nonrecursive queries between themselves. Do not list a nonrecursive name server as a forwarder . When a name server is using another server as a forwarder, it sends the query to the forwarder as a recursive query instead of a nonrecursive query. |
|