dns (nrcmd)							dns (nrcmd)


NAME
    dns - Configures and controls the DNS server

SYNOPSIS
    dns disable <attribute>
    dns enable <attribute>
    
    dns get <attribute>
    dns set <attribute>=<value> [attribute>=<value ...]
    dns unset <attribute>
    dns show
    
    dns findRR -name <fqdn>|<addr>
    dns findRR [-namePrefix <namePrefix>] [-rrTypes <rrTypeList>]
               [-protected | -unprotected] [-zoneType forward | reverse
                | primary | secondary | published | unpublished | ALL]

    dns addRootHint <name> <addr> [<addr> ...]
    dns removeRootHint <name>
    dns listRootHints
    
    dns addException <name> <addr> [<addr> ...]
    dns removeException <name>
    dns listExceptions
    
    dns addForwarder <addr>
    dns removeForwarder <addr>
    dns listForwarders
    
    dns flushCache

    dns rebuildRR-Indexes

    dns forceXfer secondary

    dns scavenge

    dns serverLogs show
    dns serverLogs nlogs=<nlogs> logsize=<logsize>

    dns getStats [performance | query | errors | security | maxcounters |
                  ha | ipv6 | all] [total | sample]
    dns resetStats


    dns getZoneCount [forward | reverse | primary | secondary | published |
                      unpublished | ALL]
    dns getRRCount [zone <name> | forward | reverse | primary | secondary |
                    published | unpublished | ALL]

    dns removecachedRR <name> [<type>] [<data>]

    dns setPartnerDown
    
DESCRIPTION
    The dns command lets you configure the DNS server in the cluster. 

    dns findRR -name <fqdn>|<addr>
    dns findRR [-namePrefix <namePrefix>] [-rrTypes <rrTypeList>]
               [-protected | -unprotected] [-zoneType forward | reverse
                | primary | secondary | published | unpublished | ALL]
       Use the findRR commands to display the resource records for a
       specific domain name; or to display those matching a name prefix, 
       a list of resource record types--whether protected or unprotected--and 
       certain zone types.

    dns addRootHint <name> <addr> [<addr> ...]
    dns removeRootHint <name>
    dns listRootHints
       Use the RootHint commands to add or remove the names
       and addresses of the root servers. After you specify the
       root servers, Network Registrar queries them for their 
       root name server records.  These records are in turn used 
       to resolve other names. As such, these values need not be 
       exact, but must be accurate enough for the Network Registrar 
       DNS server to retrieve the correct information.
    
       The addRootHint command adds the name of a root server and the
       addresses (to which it is listening on) to the list that the DNS
       server uses to find the roots of the DNS name space.
    
       The removeRootHint command removes a root server from the list.
    
       The listRootHints command lists the root server information.
    
    dns addException <name> <addr> [<addr> ...]
    dns removeException <name>
    dns listExceptions
       Use the exception commands only if you do not want 
       your DNS server to use the standard name resolution 
       for querying root name servers for names outside the domain.
       The exception command lets you specify the resolution 
       exception domains and the IP addresses of the associated 
       servers.
    
       The addException command adds a list of DNS servers to use
       to resolve names in a specified domain. This list allows you
       to override DNS the publicly configured names server for one
       or more domains.
    
       The removeException command removes an entry for exceptional 
       resolution of addresses within a domain.
    
       The listExceptions command lists the domains that are configured
       to have exceptional resolution of their names.

    dns addForwarder <addr>
    dns removeForwarder <addr>
    dns listForwarders
       Use the Forwarder commands to specify the addresses of any name
       servers that you want your Network Registrar DNS server to use 
       as forwarders. Network Registrar forwards recursive queries to 
       these servers before forwarding queries to the Internet at-large.
       You can use the exception command to override forwarding for
       specific domains.
    
       The addForwarder command adds the address of a forwarder for 
       this DNS server.
    
       The removeForwarder command removes the address of a forwarder.
    
       The listForwarders command lists the forwarders for this DNS 
       server.
  
    dns flushCache
        The flushCache command flushes the persistently cached 
        information in the DNS server. To remove cached information, to be removed,
        reload the DNS server.

    dns rebuildRR-Indexes

       The rebuildRR-Indexes command rebuilds the resource record 
       indexes.

    dns forceXfer secondary
       The forceXfer command forces full zone transfers for every zone       
       whose type matches the type (primary or secondary) specified in 
       the command, regardless of the SOA serial numbers, to synchronize
       DNS data store.  If a normal zone transfer is already in progress, 
       the forceXfer command schedules a full zone transfer for that 
       zone immediately after the normal zone transfer finishes. 

       Note: The option for primary is not yet available.

    dns scavenge
       The scavenge command causes scavenging to occur on all primary 
       zones that have scavenge enabled. 
	
    dns serverLogs show
    dns serverLogs nlogs=<nlogs> logsize=<logsize>
       The serverLogs show command displays the number of log files
       and the maximum size for each file.
    
       The serverLogs command allows setting the two server logging 
       parameters, nlogs and logsize.  Either or both may be specified
       in the command, and changes will only occur to the one(s) 
       specified.  When setting logsize, a suffix of K or M indicates
       units of thousands or millions.  
  
          dns serverLogs nlogs=6 logsize=500K
          dns serverLogs logsize=5M

       Note: For these changes to take effect you must save the changes
       and restart the server Agent.

    
    dns getStats [performance | query | errors | security | maxcounters |
                  ha | ipv6 | all] [total | sample]
    dns resetStats
       The getStats command displays the requested DNS server 
       statistics, either since the last reload or for the last sample
       period.
       The resetStats commands returns the DNS activity counters 
       (statistics) to zero.

   
    dns getZoneCount [forward | reverse | primary | secondary | published |
                      unpublished | ALL]
    dns getRRCount [zone <name> | forward | reverse | primary | secondary |
                    published | unpublished | ALL]
       The getZoneCount and getRRCount commands display the number of 
       zones or resource records for the requested zones. By default, 
       all published zones are reported.

    dns removecachedRR <name> [<type>] [<data>]
       The removecachedRR comand allows the removal of non-authoritative
       RRs from both the (non-authoritative) persistent cache and 
       the in-memory cache. An RR name-set can be removed by supplying
       only 'name'. An RR-set can be completely removed by specifying  
       both 'name' and 'type'; a specific RR can be purged by supplying 
       'name', 'type' and 'data'.

    dns setPartnerDown
       The setParterDown command notifies the DNS server that its High
       Availability DNS partner server is down.

EXAMPLES

STATUS

SEE ALSO
    server

PROPERTIES
  Attributes:

    activity-counter-interval[142] (AT_RANGETIME, Optional, default: 5m)
        Sets the period of time that server activity counters use to
        collect metrics.
        Use this attribute together with the 'collect-sample-counters'
        attribute.  Make sure the 'collect-sample-counters' is set to
        true (enable) to start sampling.

    activity-counter-log-settings[141] (AT_FLAGSINT(), Optional, default: total,performance,query,errors,security,maxcounters,ha,ipv6)
        Controls what activity counters a DNS server uses for logging.
        The possible flags are:
          total        log the accumulated counters since reset or server
                       start.
          sample       log counters for each sampling interval.
          performance  log performance-related counters.
          query        log query-related counters.
          errors       log error-related counters.
          security     log security-related counters.
          maxcounters  log maxcounters-related counters.
          ha           log HA-related counters.
          ipv6         log IPv6-related counters.

    activity-summary-interval[127] (AT_RANGETIME, Optional, default: 5m)
        Sets the seconds between DNS activity summary log messages,
        if the activity-summary attribute is enabled in the server
        log-settings. The default value is 5 minutes.

    auth-db-cache-kbytes[88] (AT_INT, Optional, default: 10240)
        Sets the kilobytes of internal (BTREE) cache that the authzone
        database uses.
        Note: This value is rounded up to the nearest 4KB boundary. For
        example, an 81KB value is rounded up to 84KB.

    axfr-multirec-default[30] (AT_BOOL, Optional, default: on)
        Determines the default multi-record AXFR choice for
        foreign (remote) servers not found in remote server list.
        Default is true (enable). Only old version Bind 8.x and
        Microsoft NT version require this attribute to set false.

    cache-db-cache-kbytes[89] (AT_INT, Optional, default: 10240)
        Sets the kilobytes of internal (BTREE) cache that the cache database
        uses.
        Note: This value is rounded up to the nearest 4KB boundary. For
        example, an 81KB value is rounded up to 84KB.

    checkpoint-interval[79] (AT_RANGETIME, Optional, default: 3h)
        Sets the seconds that elapse between snapshots of zone information.
        DNS records this information in the Zone Checkpoint database.

    collect-sample-counters[140] (AT_BOOL, Optional, default: true)
        Switches counter sampling on and off.

    default-negcache-ttl[148] (AT_RANGETIME, Optional, default: 0)
        Sets the amount of time in seconds that the DNS server caches
        negative answers if there is no SOA record in the authority
        section of the reply.
        The presence of an SOA record in the authority section of a
        negative overrides this attribute value.
        For more details, see IETF RFC2308.

    delegation-only-domains[143] (AT_NLIST(AT_DNSNAME), Optional, default: <none>)
        
        Instructs the DNS server to expect a specified zone to
        return only delegations to authoritative nameservers
        when queried.
        Other than records at the domain name itself, the
        specified zone must contain only NS records for each each
        nameserver to which the subzone is delegated and the zone's
        apex SOA record.  For example, 'com.' is a domain that should
        contain only delegations.
        Use this attribute to filter out wildcard or synthesized data
        from authoritative nameservers whose undelegated (in-zone) data
        is of no interest.
        The server enforces the delegation-only nature of the domains on
        this list when it examines responses that are not from a
        forwarder or resolution exception server. The server converts
        non-conforming answers to no-such-name responses.  This cannot
        be enforced when the answer comes from a forwarder.

    exception-forwarding[188] (AT_ENUMINT(), Optional, default: forward-last)
        Controls the order (forward-first, forward-last or forward-always)
        with which the DNS server will forward a query to a configured
        resolution exception.
        forward-always - DNS will always forward queries to a configured
                 	 exception
        forward-first  - DNS will first forward queries to a configured 
        	         exception and if it doesn't get an answer 
        		 before the request expires, it will forward to 
        	         cached name servers (if any)
        forward-last   - DNS will first forward queries to cached name 
        		 servers (if any) and if it doesn't get an answer 
        		 before the request expires, it will forward the 
        		 query to a configured exception

    fake-ip-name-response[86] (AT_BOOL, Optional, default: enabled)
        
        Controls whether the DNS server rejects queries of fully
        qualified domain names that are in IP address form (for
        example, an A record like 192.168.40.40), without even trying
        to query (or forward to) other servers. Default is true
        (enable).
        Enabling this feature causes the server to respond to these
        queries indicating the name does not exist.   Queries of this
        type are generally from rogue applications.

    forward-retry-time[154] (AT_RANGETIME, Optional, default: 8s)
        Sets the retry interval for forwarding a DNS query to a
        forwarder or resolution exception server. These queries are
        recursive, and may require more time for the forwarder to
        resolve.
        To ensure the server tries all forwarders, set this value to the
        'request-expiration-time' divided by one less than the total
        number of configured forwarders).
        Note:  This attribute has no affect when you enable slave-mode;
        the server uses slave-forward-retry-time instead.

    ha-dns-comm-timeout[163] (AT_RANGETIME, Optional, default: 30s)
        Sets the period of time that must elapse before the server
        determines it cannot communicate with its HA DNS partner.

    ixfr-enable[32] (AT_BOOL, Optional, default: enabled)
        Controls the incremental transfer behavior for zones for
        which you have not configured a specific behavior. Required,
        true (enable).

    ixfr-expire-interval[38] (AT_RANGETIME, Optional, default: 0)
        Specifies the maximum duration between full zone transfers that 
        the DNS server will request incremental transfer updates for its 
        secondary zones.  After this time interval expires, even if an 
        incremental transfer would normally be requested, the DNS server 
        will instead request a full zone transfer.  Setting this value 
        to 0 does not enforce any time limit between full zone transfers.

    local-port-num[10] (AT_RANGEINT(1-65535), Optional, default: 53)
        Specifies the UDP and TCP port number that the DNS server
        uses to listen for queries.

    log-settings[80] (AT_FLAGSINT(), Optional, default: config,ddns,xfr-in,xfr-out,notify,datastore,scavenge,server-operations,root-query,tsig,query-errors,ha-details)
        Determines which detailed events the DNS server logs, as set
        using a bit mask. Logging these additional details can help
        analyze a problem. Leaving detailed logging enable for a long
        period, however, can fill the log files and cause the loss of
        important information.
        The possible flags are:
          config
            This flag will cause log messages pertaining to server
            configuration and server de-initialization (unconfiguration).
          ddns
            This flag will cause the logging of high-level DDNS messages.
            Detailed DDNS logging (e.g. RRs that have been deleted or
            added) can be enabled via ddns-details.
          xfr-in
            This flag will allow the generation of log messages
            associated with inbound full and incremental zone transfers.
          xfr-out
            This flag will allow the generation of log messages
            associated with outbound full and incremental zone transfers.
          notify
            This flag allows log messages associated with the processing
            of notify messages.
          datastore
            This flag allows the generation of log messages associated
            with datastores processing. Enabling this flag provides
            insight into various events in the server's embedded
            databases/datastores.
          scavenge
            This flag allows the logging of events associated (RR)
            scavenging.
          scavenge-details
            This flag causes more detailed logging, pertaining to
            scavenging, to be displayed. Note, this flag is disabled by
            default.
          server-operations
            This flag enables the logging of general high server events
            (such as those pertaining to sockets and interfaces).
          lame-delegation
            This flag allows the logging of lame-delegation events.
            Though enabled by default, disabling this flag could prevent
            the log from getting filled with frequent lame-delegation
            encounters.
          root-query
            This flag allows the generation of log messages associated
            queries (and responses) from root servers.
          ddns-refreshes
            This flag allows the server to log messages associated with
            (W2K) DDNS refreshes.
          ddns-refreshes-details
            This flag generates log messages that provide details
            describing RRs that were refreshed.
          ddns-details
            This flag enables detailed logging that describes the RR(s)
            that have deleted/added due to DDNS updates.
          tsig
            This flag allows the logging of events associated Transaction
            Signature (TSIG) DDNS updates.
          tsig-details
            This flag causes more detailed logging, pertaining to tsig, to
            be displayed. Note, this flag is disabled by default.
          query-errors
            This flag causes logging of errors encountered while
            processing DNS queries.
          config-details
            This flag generates detailed information during server
            configuration (e.g. displaying all configured and assumed
            server attributes)
          incoming-packets
            This flag causes incoming packets to be traced.
          outgoing-packets
            This flag causes outgoing packets to be traced.
          xfr-in-packets
            This flag causes incoming zone transfer packets to be traced.
          xfr-out-packets
            This flag causes outgoing zone transfer packets to be traced.
          query-packets
            This flag causes query packets to be traced.
          notify-packets
            This flag causes notify packets to be traced.
          ddns-packets
            This flag causes DDNS packets to be traced.
          performance
            This flag logs server level performance statistics.
          ha-details
            This flag enables detailed logging of HA related information.

    max-cache-ttl[20] (AT_RANGETIME, Optional, default: 1w)
        Sets the maximum amount of time that you want the DNS server
        to retain cached information.  Default is 604800s (1w).

    max-dns-packets[151] (AT_INT, Optional, default: 500)
        Specifies the maximum number of packets that dns server will
        handle concurrently. DNS server will drop inbound packets if this
        limit is reached.

    max-negcache-ttl[119] (AT_RANGETIME, Optional, default: 60m)
        Sets an upper limit on the number of seconds a DNS server
        maintains negative cache entries. Default is 3600s (1h).
        A server generates these cache entries after querying another
        name server and receiving an authoritative reply stating the
        requested records do not exist.

    mem-cache-size[21] (AT_RANGEINT(200-4194303), Optional, default: 50000)
        Indicates the size, in kilobytes, of the in-memory record cache.
        Default is 50000 (50MB).

    minimal-responses[191] (AT_BOOL, Optional, default: false)
        Controls whether the DNS server omits or includes records from
        the authority and data sections of query responses when these 
        records are not required. Enabling this attribute may improve
        query performance such as when the DNS server is configured as
        a caching server.

    no-fetch-glue[14] (AT_BOOL, Optional, default: disabled)
        Specifies whether you want the DNS server, when composing
        a response to a query, to fetch missing glue records.
        Glue records are DNS A records, which specify the address of a
        domain's authoritative name servers. Normal DNS responses include
        NS records and their A records related to the name being queried.

    no-recurse[15] (AT_BOOL, Optional, default: disabled)
        Specifies whether you want to disable forwarding client queries
        to other name servers when your DNS server is
        not authoritative for data in its own cache. If you disable
        recursive queries, you make your name server a noncaching server.

    notify[39] (AT_BOOL, Optional, default: enabled)
        Controls how the DNS server sends NOTIFY packets for zones
        that have changed. Default is true (enable).
        You must also set these attributes or accept their defaults:
        notify-defer-cnt, notify-min-interval, notify-rcv-internal,
        notify-send-stagger, notify-wait.

    notify-defer-cnt[43] (AT_INT, Optional, default: 100)
        With the notify attribute enabled, sets the maximum number of
        changes the DNS server can accumulate during the notify-wait
        period. If changes exceed this number, the DNS server sends
        notification before the notify-wait period has elapsed.
        Default is 100 changes.

    notify-min-interval[41] (AT_RANGETIME, Optional, default: 2s)
        With the notify attribute enabled, sets the minimum interval
        required before sending notification to a particular server of
        consecutive changes on the same zone. Default is 2s.

    notify-rcv-interval[44] (AT_RANGETIME, Optional, default: 5s)
        With the notify attribute enabled for secondary zones, sets the
        minimum amount of time between complete processing of one
        notification (serial number testing and/or zone transfer), and
        the start of processing of another notification. ,
        default 5s.

    notify-send-stagger[40] (AT_RANGETIME, Optional, default: 1s)
        With the notify attribute enabled, sets the interval
        to use for staggering notifications to multiple servers
        about a zone change. Default is 1s.

    notify-source-address[167] (AT_IPADDR, Optional, default: <none>)
        Specifies the source IP address that the DNS server uses to send
        notify requests to other servers. A value of 0.0.0.0 indicates
        that operating systen uses the best local address based on the
        destination.

    notify-source-port[166] (AT_RANGEINT(0-65535), Optional, default: <none>)
        Specifies the UDP port number that the DNS server uses to send
        notify requests to other servers.
        A value of zero indicates that the server should choose a random
        port. If this attribute is unset, then queries are sent from
        the port used to listen for queries (See the local-port-num
        attribute).

    notify-wait[42] (AT_RANGETIME, Optional, default: 5s)
        With the notify attribute enabled, and after an initial zone
        change, sets the period of time for the DNS server to wait
        before it sends change notification to other name servers.
        Default is 5s.
        This property allows you to accumulate multiple changes,
        and thus limit the number of times the serial number advances.

    persist-mem-cache[150] (AT_BOOL, Optional, default: true)
        Specifies whether the DNS server writes memory chache, or reads
        it from the persistent cache database.
        If you set this to false, DNS does not use the persistent cache
        database.

    query-source-address[98] (AT_IPADDR, Optional, default: <none>)
        Specifies the source IP address from which the DNS server will
        send queries to other servers when resolving names for clients.  A
        value of 0.0.0.0 indicates that OS will use the best local address
        based on the destination.

    query-source-port[97] (AT_RANGEINT(0-65535), Optional, default: <none>)
        Specifies the UDP port number that the DNS server uses to send
        queries to other servers when resolving names for clients.  A
        value of zero instructs the server to choose a random port.  If
        you unset this attribute, the server sends queries from the
        port it uses to listen for queries (see the local-port-num
        attribute).

    remote-port-num[11] (AT_RANGEINT(1-65535), Optional, default: 53)
        Specifies the UDP and TCP port number the DNS server
        uses to send queries to other servers. Default is port 53.

    request-expiration-time[153] (AT_RANGETIME, Optional, default: 1m30s)
        Governs the expiration time of DNS queries; for example,
        DNS query, zone transfer SOA query, IXFR request and notify
        request). A query that is not answered within this time interval
        expires.
        Note: Cisco recommends that you make sure this value is
        considerably larger than 'request-retry-time' to allow multiple
        attempts to query multiple servers, using exponential backoff.

    request-retry-time[152] (AT_RANGETIME, Optional, default: 4s)
        Dictates the retry time interval (in secs) when querying a name
        server. This time interval is used in general queries - in
        response to DNS clients queries - (zone transfers) SOA queries,
        IXFR requests and notify requests. Understand that this is a
        minium retry time. The server applies an exponential backoff on
        retries.

    restrict-cache-query-acl[187] (AT_AMELST, Optional, default: <none>)
        Specifies an access control list that restricts which
        clients are allowed to query for cached non-authoritative
        resource records. If unset, restrict-query-acl is used.
        Optional.

    restrict-query-acl[144] (AT_AMELST, Optional, default: any)
        Provides a global access control list (ACL) used to limit device
        queries that a DNS server must honor. You can restrict query
        clients based on host IP address, network address, TSIG keys,
        and access control lists. The default is to allow any client to
        perform a query.
        Zones inherit this ACL if they are missing their
        restrict-query-acl. This ACL also serves as filtering queries for
        non-authoritative zones.

    restrict-recursion-acl[149] (AT_AMELST, Optional, default: any)
        Defines the global Access Control List (ACL) used to restrict
        recursive that the DNS server honors.  This list can contain
        host, network addresses, TSIG keys and global ACLs that
        restrict recursive queries to a certain set of DNS clients.
        Default is to allow any client to perform a query. For any client
        not passing this ACL andrequesting a recursive query, the server
        responds with a referal - as if originally requested with an
        iterative query.

    restrict-xfer-acl[136] (AT_AMELST, Optional, default: none)
        Overrides the default access control list (designating who can
        receive zone transfers).

    round-robin[29] (AT_BOOL, Optional, default: enabled)
        Specifies whether you want round-robin cycling of equivalent
        records in responses to queries. Equivalent records are records
        of the same name and type. Since clients often only look at the
        first record of a set, enabling this features can help balance
        loads and keep clients from forever trying to talk to an
        out-of-service host.

    save-negative-cache-entries[84] (AT_BOOL, Optional, default: enabled)
        Controls whether to have the server store negative query results.
        Default, true (enable).
        Disabling this feature prevents persistent caching of negative
        query responses.

    scvg-ignore-restart-interval[93] (AT_RANGETIME, Optional, default: 2h)
        Ensures that the server does not reset the scavenging time with
        every server restart. Within this interval, Network Registrar
        ignores the time between when a server went down and its restart.
        This interval is normally short. The value can range from two
        hours to one day. With any time longer than that set,
        Network Registrar recalculates the scavenging period
        to allow for record updates that cannot take place while the
        server is stopped. You can also set this  attribute on a zone,
        and the value set on the zone overrides the server setting.
        Default is 2h.

    scvg-interval[90] (AT_RANGETIME, Optional, default: 1w)
        Sets the seconds that DNS waits before removing (scavenging)
        out-of-date address (A) records.

    scvg-no-refresh-interval[91] (AT_RANGETIME, Optional, default: 1w)
        Sets the number of seconds during which DNS updates cannot increment
        the zone timestamp.

    scvg-refresh-interval[92] (AT_RANGETIME, Optional, default: 1w)
        Sets the number of seconds during which DNS updates can increment
        the zone timestamp. After both the no-refresh and refresh intervals
        expire, the record is a candidate for scavenging. The value
        can range from one hour to 365 days. The zone setting overrides
        the server setting of 604800s (1w).

    simulate-zone-top-dynupdate[67] (AT_BOOL, Optional, default: disabled)
        Enables compatibility with a Windows 2000 Domain Controller.
        When processing a dynamic update packet, which attempts to add
        or remove A records from the name of a zone, DNS responds as if
        the update succeeded, rather than responding with a refusal, as
        would normally occur due to the protected/unprotected name
        conflict. No update to the records at the zone name will actually
        occur, although the response indicates that it has.

    slave-forward-retry-time[156] (AT_RANGETIME, Optional, default: 30s)
        Sets the retry interval for forwarding a DNS query in slave-mode.
        These queries are recursive, and may require more time for the
        forwarder to resolve.
        To ensure the server tries all forwarders, set this value to the
        'request-expiration-time' divided by one less than the total
        number of configured forwarders.

    slave-mode[16] (AT_BOOL, Optional, default: disabled)
        Specifies whether you want this server to be a slave server; that
        is, a server that relies entirely on forwarders for data that
        is not in its cache. Default is false (disable).
        This attribute takes effect only if you specify the corresponding
        forwarders.
        Note: You can override slave-mode for specific domains with the
        exception-list property.

    subnet-sorting[57] (AT_BOOL, Optional, default: disabled)
        Controls whether DNS reorders A records when responding to client
        queries. Default is false (disable).
        As implemented in BIND 4.9.7, the Network Registrar DNS
        server confirms the clients network address before responding to
        a query. If the client, server, and target of the query are on the
        same subnet, and the target has multiple A records, the server tries
        to reorder the A records in its response by putting the targets
        closest address first in the response packet.
        Because clients often only look at the first record in a set,
        enabling this attribute can help localize network traffic onto
        a subnet. This attribute is only applied on answers to queries
        from clients located on the same subnet as the DNS server.

    tcp-query-retry-time[155] (AT_RANGETIME, Optional, default: 10s)
        Defines the retry time for DNS queries over a TCP connection.
        Cisco recommends that you set this value to less than
        'request-expiration-time'.

    transfer-source-address[169] (AT_IPADDR, Optional, default: <none>)
        Specifies the source IP address that the DNS server uses to send
        transfer and SOA requests to other servers.
        A value of 0.0.0.0 indicates that operating system uses the best
        local address based on the destination.

    transfer-source-port[168] (AT_RANGEINT(0-65535), Optional, default: <none>)
        Specifies the UDP port number that the DNS server uses to send
        transfer and SOA requests to other servers.
        A value of 0 (zero) indicates that you should choose a random port.
        If this attribute  is unset, then queries are sent from the port
        used to listen for queries (see local-port-num).

    traps-enabled[165] (AT_FLAGSINT(), Optional, default: <none>)
        Defines the traps that this server is configured to send.
           1  all
              Sends notifications for all server events.
           2  server-start
              Sends notifications whenever the server is started or 
              reinitialized.
           3  server-stop
              Sends notifications whenever the server is stopped.
           4  ha-dns-partner-down
              Sends notifications whenever the HA DNS partner 
              goes down.      
           5  ha-dns-partner-up
              Sends notifications whenever the HA DNS partner becomes 
              available again after going down.
           6  ha-dns-config-error
              Sends notifications when a configuration mismatch between 
              HA DNS partners occurs.
           7  masters-not-responding
              Sends notifications when master servers stop responding.
           8  masters-responding
              Sends notifications when master servers start responding 
              again.
           9  secondary-zone-expired
              Sends notifications when a secondary server can no longer 
              claim authority for zone data when responding to queries
              during a zone transfer.
           10 forwarders-not-responding
              Sends notifications when DNS forwarders stop responding.
           11 forwarders-responding
              Sends notifications when DNS forwarders start responding
              again.

    update-acl[122] (AT_AMELST, Optional, default: none)
        Provides server-level control of which devices can access and
        update the DNS server. If the access control list is set at the
        zone level, Network Registrar overrides the server-level setting.

    update-relax-zone-name[45] (AT_BOOL, Optional, default: disabled)
        Enables DNS updates to specify any zone name in the authoritative
        zone rather than the exact zone name; thus, relaxing the RFC 2136
        restriction on the zone name record in dynamic updates. This
        attribute allows updates to specify a zone name which is any name
        within an authoritative zone rather than exactly the name of a zone.

