Failed to add multiple zone-transfer addresses in IdM managed DNS zone

Solution Verified - Updated -


  • Need to add multiple zone-transfer IP addresses in IdM managed DNS zone to: and
  • Followed example in Product Documentation1 to enable zone-transfer with command line: ipa dnszone-mod --allow-transfer=;
  • Only one IP address was added successfully

    # ipa dnszone-mod --allow-transfer=;
    Zone name:
    Active zone: TRUE
    Authoritative nameserver:
    Administrator e-mail address:
    SOA serial: 1602066022
    SOA refresh: 3600
    SOA retry: 900
    SOA expire: 1209600
    SOA minimum: 3600
    Allow query: any;
    Allow transfer:;             <=== Only one IP address was added
  • Multiple IP addresses can be added via Web UI successfully

  1. Linux Domain Identity, Authentication, and Policy Guide: 33.4.3. Enabling Zone Transfers 


  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8
  • Red Hat Identity Management (IdM) / FreeIPA
    • ipa-server
    • ipa-server-dns
    • bind-pkcs11 / named-pkcs11.service

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In