Our BIND9 installations (on 141.42.1.11, 2.22, 3.33 and 196.196) are slaves for the zone vdi.charite.de:
29-Dec-2016 14:28:31.082 general: zone vdi.charite.de/IN: notify from 10.32.32.51#53930: serial 13301424
29-Dec-2016 14:28:31.085 general: zone vdi.charite.de/IN: Transfer started.
29-Dec-2016 14:28:31.144 general: zone vdi.charite.de/IN: transferred serial 13301424
And, although all of our internal DNS servers are merely slaves for the vdi zone, we're still seeing NOTIFY from the other slave servers:
29-Dec-2016 14:28:31.623 general: zone vdi.charite.de/IN: refused notify from non-master: 141.42.2.22#36708
29-Dec-2016 14:28:31.637 general: zone vdi.charite.de/IN: refused notify from non-master: 141.42.3.33#59869
29-Dec-2016 14:28:31.639 general: zone vdi.charite.de/IN: refused notify from non-master: 141.42.196.196#37013
Why? How can I turn this off?
The zone is defined:
zone "vdi.charite.de" {type slave; file "vdi.charite.de"; masters { 10.32.32.51; 10.47.120.201; }; };
and our options include:
notify yes; // send DNS NOTIFY
That is expected behavior, From BIND 9 Administrator Reference Manual:
page 15:
but also
and in more detail on page 88: