Oracle RAC - knot.conf, remotes and zones
Oracle RAC Solution · Config document · referenced from DNS server: Knot
The part of the Knot DNS configuration that I added on dns1: one remote, which is the server itself, and five zones, each with its zone file and with zone transfer allowed to that remote. The notes show only these two blocks; the rest of the file was left as the Debian package delivered it and is marked here with a comment line.
| Item | Value |
|---|---|
| Path on the host | /etc/knot/knot.conf |
| Host | dns1 (10.30.40.13), Debian 8.5 |
| Software | Knot DNS from the Debian package knot, installed with apt-get install knot; the notes do not record the version (Debian 8 carried 1.6.0) |
| Shown here | the added remotes block and the zones added to the zones section |
| Applied with | /etc/init.d/knot restart |
The file
# ... (the packaged knot.conf continues here; the notes do not show it) # Definition of Knot aliases for IP addresses. # Declare just one server: the one the "knot" DNS server itself runs on. Allow a zone transfer for "this-server" below. remotes { this-server { address 10.30.40.13@53; } } # ... (the packaged knot.conf continues here; the notes do not show it) zones { # The DNS zone "example.net", using the zone file "/etc/knot/example.net.zone" and allowing a zone transfer initiated from the DNS server itself (this-server). example.net { file "/etc/knot/example.net.zone"; xfr-out this-server; } # The reverse DNS zone "10.30.10.in-addr.arpa", using the zone file "/etc/knot/10.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server). 10.30.10.in-addr.arpa { file "/etc/knot/10.30.10.in-addr.arpa"; xfr-out this-server; } # The reverse DNS zone "20.30.10.in-addr.arpa", using the zone file "/etc/knot/20.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server). 20.30.10.in-addr.arpa { file "/etc/knot/20.30.10.in-addr.arpa"; xfr-out this-server; } # The reverse DNS zone "30.30.10.in-addr.arpa", using the zone file "/etc/knot/30.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server). 30.30.10.in-addr.arpa { file "/etc/knot/30.30.10.in-addr.arpa"; xfr-out this-server; } # The reverse DNS zone "40.30.10.in-addr.arpa", using the zone file "/etc/knot/40.30.10.in-addr.arpa" and allowing a zone transfer initiated from the DNS server itself (this-server). 40.30.10.in-addr.arpa { file "/etc/knot/40.30.10.in-addr.arpa"; xfr-out this-server; } # ... (the packaged knot.conf continues here; the notes do not show it)
What the lines do
| Line | Meaning |
|---|---|
remotes { this-server { address 10.30.40.13@53; } } | Gives the address and port of the DNS server itself a name that the zone blocks can refer to |
file "/etc/knot/example.net.zone"; | The zone file of the zone; every zone has its own file in /etc/knot |
xfr-out this-server; | Allows a zone transfer of this zone to the named remote, here only to the server's own address |
The zone transfer is allowed for one purpose: the tests. With xfr-out this-server a dig @10.30.40.13 <zone> axfr run on dns1 itself prints the whole zone as the server loaded it, which is how the mistakes in the reverse zones became visible. No secondary DNS server exists in the notes, and no other host may transfer the zones.
The five zone files are Config documents of their own.
| Zone | Zone file | Config document |
|---|---|---|
example.net | /etc/knot/example.net.zone | Zone example.net |
10.30.10.in-addr.arpa | /etc/knot/10.30.10.in-addr.arpa | Reverse zone, public network |
20.30.10.in-addr.arpa | /etc/knot/20.30.10.in-addr.arpa | Reverse zone, interconnect network |
30.30.10.in-addr.arpa | /etc/knot/30.30.10.in-addr.arpa | Reverse zone, backup network |
40.30.10.in-addr.arpa | /etc/knot/40.30.10.in-addr.arpa | Reverse zone, management network |
There is no zone for the iSCSI network 10.30.50.x.
Checked against Knot DNS 3.6.0
Debian 8 carried Knot DNS 1.6.0, so that is most likely what the package installed; the notes do not say. The last 1.6 release was 1.6.8 in August 2016. The current stable branch is 3.6.0 of September 2026, and Debian 13 ships 3.4.6.
| As built | Today |
|---|---|
| Configuration in the 1.x format with blocks in braces | Replaced in Knot 2.0.0 (June 2015) by a YAML text format. No 2.x or 3.x server reads a 1.x file |
remotes as a list of servers whose role is decided where they are used | remote: describes outgoing connections only, such as the source of a transfer or the target of a notification |
xfr-out this-server; to permit a transfer | An acl: rule with action: transfer, matched on address or TSIG key and referenced from the zone's acl |
| Five zone blocks that repeat the same option | A template: with the identifier default applies to every zone |
| No converter needed in 2016 | The converter knot1to2 shipped with 2.0 to 2.4 and was removed in 2.5.0; today the file is rewritten by hand |
/etc/init.d/knot restart after every change | knotc reload or knotc zone-reload for changed zone files, knotc conf-check for the configuration; no restart is needed for a zone edit |
The meaning of the two statements has not changed, only where they are written: in 1.6 xfr-out named the remotes "permitted to obtain zone's contents via zone transfer", and the transfer to the server's own address worked because the query came from the listed address. Knot DNS downloads and supported versions.