DNS Question
Posted in 2000
Topics: Connectivity: ODBC / JDBC / .NET, Server Administration, Platform-Specific Issues
I am an Informix DBA running Informix 7.3 UC7 on an IBM AIX 4.1.3 rs/6000 box. Recently, we had a network problem where one of the two DNS servers in our Unix server's table became unavailable. The Informix application began to slow down and eventually new users were unable to get into the application. (The application uses a daemon process listening on a port for authentication and sql statements.) My Unix support people tell me that the second entry in the DNS table should be automatically be working. After I protested that users were not able to get their work done, the Unix adminstrators altered the DNS table to put the "bad" server address behind the "good" one. They said this would take effect immediately and is a dynamic change. It had no effect. The next thing that was done was to remove the "bad" entry altogether. Again, no effect. Finally, we rebooted the Unix box and the app came up fine. We asked the vendor of the app whether they do any DNS lookups. The response was that any DNS requests are sent to Informix, and it is Informix that actually issues DSN lookup requests. My network people tell me that there is no reason why the Unix box would have to be rebooted UNLESS the application directly used or cached the Unix DNS tables. Looking at application logs, Informix logs, and Unix logs did not shed any light as to what the problem was since none of them reported any problem. The question I have is if an app requests Informix to do a DNS lookup, exactly what does it do and how does it do it. Other than user's complaining about app response time (or inability to get into the app), I currently have no way of knowing what the problem is or how to go about solving it. Specifically, I can't answer the question as to why the Unix server reboot solved the problem, and how to go about diagnosing this type of problem in the future. Any help members of the forum can shed on this problem would be greatly appreciated. -- Thanks GM Sent via Deja.com http://www.deja.com/ Before you buy.
*cracks out the old dns manuals* Not too sure about 413, but from the books: Your box sounds like its slaving off to another set of machines, named (depending on which version you are running) does not see changes in its config files unless told to look for it, best thing would have been: stopsrc -s named; startsrc -s named no need for a reboot. Now, tell us something, the slowdown, was that just informix or did all the processes which use dns start doing thier nuts? telnet loves this problem for instance. What messages were in the informix log file? check em out. also, errpt -a would reveal information if its there, don't be too hopefull. Personally it sounds like the authentication mechanism informix is using, if you require the .rhosts or hosts.equiv, I'd say that the machine could not look lookup the host names to see the authentication allowed. Solution, if you are running on a simple enough lan, slap em ALL into your hosts file and tell AIX to go hosts first. brett In article <8pofni$654$1@nnrp1.deja.com>, gmoskowitz@buckconsultants.com says... > I am an Informix DBA running Informix 7.3 UC7 on an IBM AIX 4.1.3 > rs/6000 box. Recently, we had a network problem where one of the two > DNS servers in our Unix server's table became unavailable. The Informix > application began to slow down and eventually new users were unable to > get into the application. (The application uses a daemon process > listening on a port for authentication and sql statements.) My Unix > support people tell me that the second entry in the DNS table should be > automatically be working. After I protested that users were not able to > get their work done, the Unix adminstrators altered the DNS table to > put the "bad" server address behind the "good" one. They said this > would take effect immediately and is a dynamic change. It had no > effect. The next thing that was done was to remove the "bad" entry > altogether. Again, no effect. Finally, we rebooted the Unix box and the > app came up fine. > > We asked the vendor of the app whether they do any DNS lookups. The > response was that any DNS requests are sent to Informix, and it is > Informix that actually issues DSN lookup requests. My network people > tell me that there is no reason why the Unix box would have to be > rebooted UNLESS the application directly used or cached the Unix DNS > tables. Looking at application logs, Informix logs, and Unix logs did > not shed any light as to what the problem was since none of them > reported any problem. > > The question I have is if an app requests Informix to do a DNS lookup, > exactly what does it do and how does it do it. Other than user's > complaining about app response time (or inability to get into the app), > I currently have no way of knowing what the problem is or how to go > about solving it. Specifically, I can't answer the question as to why > the Unix server reboot solved the problem, and how to go about > diagnosing this type of problem in the future. > > Any help members of the forum can shed on this problem would be greatly > appreciated. > > -- > Thanks > > GM > > > Sent via Deja.com http://www.deja.com/ > Before you buy. >
Thanks very much for your response. To answer your questions:
1. We are running AIX 4.3.2, not 4.1.3, my mistake.
2. The errpt -a did not show any problem, as you expected.
3. There were no error messages in any Informix logs, or in the app log
either.
4. The network contains almost 2000 users who's address is determined
by DHCP servers, so it's not reasonable to put all the addresses in the
hosts file on the Unix box.
5. Telnet sessions did not seem to be affected. Even though app users
had problems, I was able to Telnet to the box, use dbaccess, start and
stop the app daemon process, all without any noticable problem.
6. The question that I still have is: how exactly does Informix request
DNS information if an app sends the request to Informix? Does Informix
read the Unix DNS server table and use it? Does Informix read the table
once and cache it? Are there any known Informix bugs or problems in
this area?
Thanks in advance for your help.
GM
In article <MPG.142aa08129d4c4279896b2@news.dbn.lia.net>,
bofh@mailbox.co.za (bob) wrote:
> *cracks out the old dns manuals*
>
> Not too sure about 413, but from the books:
>
> Your box sounds like its slaving off to another set of machines,
> named (depending on which version you are running) does not see
> changes in its config files unless told to look for it, best thing
> would have been:
>
> stopsrc -s named; startsrc -s named
>
> no need for a reboot. Now, tell us something, the slowdown, was
> that just informix or did all the processes which use dns start
> doing thier nuts? telnet loves this problem for instance.
>
> What messages were in the informix log file? check em out. also,
> errpt -a would reveal information if its there, don't be too
> hopefull.
>
> Personally it sounds like the authentication mechanism informix
> is using, if you require the .rhosts or hosts.equiv, I'd say that
> the machine could not look lookup the host names to see the
> authentication allowed.
>
> Solution, if you are running on a simple enough lan, slap em ALL
> into your hosts file and tell AIX to go hosts first.
>
> brett
>
--
Thanks
GM
Sent via Deja.com http://www.deja.com/
Before you buy.
Thanks very much for your response. To answer your questions:
1. We are running AIX 4.3.2, not 4.1.3, my mistake.
2. The errpt -a did not show any problem, as you expected.
3. There were no error messages in any Informix logs, or in the app log
either.
4. The network contains almost 2000 users who's address is determined
by DHCP servers, so it's not reasonable to put all the addresses in the
hosts file on the Unix box.
5. Telnet sessions did not seem to be affected. Even though app users
had problems, I was able to Telnet to the box, use dbaccess, start and
stop the app daemon process, all without any noticable problem.
6. The question that I still have is: how exactly does Informix request
DNS information if an app sends the request to Informix? Does Informix
read the Unix DNS server table and use it? Does Informix read the table
once and cache it?
Thanks in advance for your help.
GM
In article <MPG.142aa08129d4c4279896b2@news.dbn.lia.net>,
bofh@mailbox.co.za (bob) wrote:
> *cracks out the old dns manuals*
>
> Not too sure about 413, but from the books:
>
> Your box sounds like its slaving off to another set of machines,
> named (depending on which version you are running) does not see
> changes in its config files unless told to look for it, best thing
> would have been:
>
> stopsrc -s named; startsrc -s named
>
> no need for a reboot. Now, tell us something, the slowdown, was
> that just informix or did all the processes which use dns start
> doing thier nuts? telnet loves this problem for instance.
>
> What messages were in the informix log file? check em out. also,
> errpt -a would reveal information if its there, don't be too
> hopefull.
>
> Personally it sounds like the authentication mechanism informix
> is using, if you require the .rhosts or hosts.equiv, I'd say that
> the machine could not look lookup the host names to see the
> authentication allowed.
>
> Solution, if you are running on a simple enough lan, slap em ALL
> into your hosts file and tell AIX to go hosts first.
>
> brett
>
--
Thanks
GM
--
Thanks
GM
Sent via Deja.com http://www.deja.com/
Before you buy.
Morning,
AIX 4.3.2 has some problems (which o/s doesn't though), recommend
upgrade to 4.3.3, though that breaks some tools which reference
the kernel structures directly (eg top and monitor).
Lets see, no errpt -a problems, no informix messages, herm. No telnet
problems, this one gets interesting.
I'm not sure of the informix mechanisms, just what I remember from
some sites I've wandered thru, check your authentication mechanism
specified in the sqlhosts file, better yet, can you whup a copy
to us?
I understand the problem with the DNS ;) Little bummer to
handle that one, so I take it your server is slaving, ok, which
version of the named are you running?
Right, the attack is:
1) Log a call with tech support, no point in not opening all
avenues
2) Hit me with a copy of your sqlhosts file, am at brett@brabys.co.za
3) Check the named version
4) Once the server 'stops' responding to your clients, telnet to the
port and see that it opens a connection, once it does, drop the
connect, you should see a report in the onstat -m about this.
If 4 does not open a connection, then I'd suggest the problem goes
deeper than authentication. If it does, then we look at the
authentication mechanism, I saw something in the manual somewhere
about it (ducks while tech support throws something)
lets see what we can do
brett
In article <8pr20m$7nc$1@nnrp1.deja.com>, gmoskowitz@buckconsultants.com
says...
> Thanks very much for your response. To answer your questions:
>
> 1. We are running AIX 4.3.2, not 4.1.3, my mistake.
> 2. The errpt -a did not show any problem, as you expected.
> 3. There were no error messages in any Informix logs, or in the app log
> either.
> 4. The network contains almost 2000 users who's address is determined
> by DHCP servers, so it's not reasonable to put all the addresses in the
> hosts file on the Unix box.
> 5. Telnet sessions did not seem to be affected. Even though app users
> had problems, I was able to Telnet to the box, use dbaccess, start and
> stop the app daemon process, all without any noticable problem.
> 6. The question that I still have is: how exactly does Informix request
> DNS information if an app sends the request to Informix? Does Informix
> read the Unix DNS server table and use it? Does Informix read the table
> once and cache it?
>
> Thanks in advance for your help.
>
> GM
>
>
> In article <MPG.142aa08129d4c4279896b2@news.dbn.lia.net>,
> bofh@mailbox.co.za (bob) wrote:
> > *cracks out the old dns manuals*
> >
> > Not too sure about 413, but from the books:
> >
> > Your box sounds like its slaving off to another set of machines,
> > named (depending on which version you are running) does not see
> > changes in its config files unless told to look for it, best thing
> > would have been:
> >
> > stopsrc -s named; startsrc -s named
> >
> > no need for a reboot. Now, tell us something, the slowdown, was
> > that just informix or did all the processes which use dns start
> > doing thier nuts? telnet loves this problem for instance.
> >
> > What messages were in the informix log file? check em out. also,
> > errpt -a would reveal information if its there, don't be too
> > hopefull.
> >
> > Personally it sounds like the authentication mechanism informix
> > is using, if you require the .rhosts or hosts.equiv, I'd say that
> > the machine could not look lookup the host names to see the
> > authentication allowed.
> >
> > Solution, if you are running on a simple enough lan, slap em ALL
> > into your hosts file and tell AIX to go hosts first.