How to remove 'additional section' from DNS reply in RHEL6
Issue
There are 2 RHEL servers (RHEL5 and RHEL6) having DNS serving several zones as forward zones to some other DNS:
# cat /etc/named.conf
...
zone "example.ru" IN {
type forward;
forward only;
forwarders { <other DNS ip>; };
};
zone "example1.ru" IN {
type forward;
forward only;
forwarders { <other DNS ip>; };
};
The problem is that during DNS query RHEL6 host returns additional section that contains list of authoritative nameservers for
[root@rhel6]# dig MX example.ru @localhost
; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.17.rc1.el6_4.6 <<>> MX kmz-tula.ru @localhost
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 17052
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 5, ADDITIONAL: 10
;; QUESTION SECTION:
;example.ru. IN MX
;; ANSWER SECTION:
example.ru. 3600 IN MX 10 mail.example.ru.
;; AUTHORITY SECTION:
ru. 172799 IN NS f.dns.ripn.net.
ru. 172799 IN NS a.dns.ripn.net.
ru. 172799 IN NS b.dns.ripn.net.
ru. 172799 IN NS e.dns.ripn.net.
ru. 172799 IN NS d.dns.ripn.net.
;; ADDITIONAL SECTION:
a.dns.ripn.net. 172799 IN A 193.232.128.6
a.dns.ripn.net. 172799 IN AAAA 2001:678:17:0:193:232:128:6
b.dns.ripn.net. 172799 IN A 194.85.252.62
b.dns.ripn.net. 172799 IN AAAA 2001:678:16:0:194:85:252:62
d.dns.ripn.net. 172799 IN A 194.190.124.17
d.dns.ripn.net. 172799 IN AAAA 2001:678:18:0:194:190:124:17
e.dns.ripn.net. 172799 IN A 193.232.142.17
e.dns.ripn.net. 172799 IN AAAA 2001:678:15:0:193:232:142:17
f.dns.ripn.net. 172799 IN A 193.232.156.17
f.dns.ripn.net. 172799 IN AAAA 2001:678:14:0:193:232:156:17
;; Query time: 46 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Wed Feb 5 13:06:13 2014
;; MSG SIZE rcvd: 372
This is a change from RHEL5 which doesn't have 'additional section':
[root@rhel5]# dig MX example.ru @localhost
; <<>> DiG 9.3.6-P1-RedHat-9.3.6-20.P1.el5_8.6 <<>> MX kmz-tula.ru @localhost
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12715
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 3
;; QUESTION SECTION:
;example.ru. IN MX
;; ANSWER SECTION:
example.ru. 3554 IN MX 10 mail.kmz-tula.ru.
;; AUTHORITY SECTION:
example.ru. 3594 IN NS ns1.example.ru.
example.ru. 3594 IN NS ns2.example.ru.
;; ADDITIONAL SECTION:
mail.example.ru. 1154 IN A XXX.XXX.XXX.XXX
ns1.example.ru. 3594 IN A XXX.XXX.XXX.XXX
ns2.example.ru. 3594 IN A XXX.XXX.XXX.XXX
;; Query time: 0 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Thu Jan 30 10:04:08 2014
;; MSG SIZE rcvd: 161
Is it possible to remove this 'additional section' from reply for particular zone or in general?
Environment
- Red Hat Enterprise Linux 5
- Red Hat Enterprise Linux 6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.