Educause Security Discussion mailing list archives

Re: Hosting Another IHE's Web Services in the Event of a Disaster


From: Jeremy Mooney <j-mooney () BETHEL EDU>
Date: Tue, 24 Oct 2006 10:15:44 -0500

Clark, Joseph K wrote on 2006/10/23 15:06:
The whole ttl question reminded me of a Slashdot article awhile back,
http://ask.slashdot.org/article.pl?sid=05/04/18/198259

It's not just DNS servers either.  Somewhat recently (probably a
1-1.5yrs ago) when moving mail services to different IPs we discovered
that there are apparently email appliance boxes doing what appeared to
be permanent caching of MX IPs (12hr TTL, they were attempting to reach
IPs that hadn't been listed it over a month).  They ended up restarting
the box(es) to troubleshoot, and that resolved the problem.  IIRC we
recommended they probably want to restart them weekly to prevent ongoing
problems until their vendor could provide a patch.  I don't remember the
vendor offhand, but I'm guessing it's not a unique problem anyways (with
mail or other all-in-one solutions).  Even if there isn't a good way to
avoid it, it's probably something to keep in mind as a known caveat when
planning any DNS-based failover.

--
Jeremy Mooney
ITS - Bethel University

Current thread: