zone (nrcmd)							zone (nrcmd)


NAME
    zone - configures a DNS zone

SYNOPSIS
    zone <name> create primary file=<hostfile> [template=<template-name>]
    zone <name> create primary <name server> <person>
                               [template=<template-name] [<attribute>=<value>...]
    zone <name> create secondary <address> [<attribute>=<value>...]
    zone <name> delete
    zone list
    zone listnames  
    zone <name> set =<value> [<attribute>=<value> ...]
    zone <name> get <attribute>
    zone <name> unset <attribute>
    zone <name> disable <attribute>
    zone <name> enable <attribute>
    zone <name> show
    
    zone <name> addHost <host name> <address> [<alias> ...]
    zone <name> removeHost <host name> 
    zone <name> listHosts  
    
    zone <name> addRR [-staged|-sync] <name> [<ttl>] [<class>] <type> <data>
    zone <name> addDNSRR <name> [<ttl>] <type> <data>
    zone <name> removeRR <name> [<type> [<data>]]
    zone <name> removeDNSRR <name> [<type>] [<data>]
    zone <name> listRR [all|ccm|dns]
    zone <name> findRR [-namePrefix <namePrefix>] 
          [-rrTypes <rrTypeList>]  [-protected | -unprotected]

    zone <name> < protect-name|unprotect-name > <name>
    zone <name> forceXfer secondary
    zone <name> syncToDns
    zone <secondary-zone-name> promote-to-primary

    zone <name> chkpt
    zone <name> dumpchkpt

    zone <name> scavenge

    zone <name> getScavengeStartTime 

    zone <name> applyTemplate <template-name>

DESCRIPTION
    The zone command lets you create and edit DNS zones.
    
    The name of the zone may be an IPv4 subnet (<address>/<length>),
    IPv6 prefix (<address>/<length>), prefix name (the prefix
    address is used), or DNS name.

    zone <name> addHost <host name> <address> [<alias> ...]
    zone <name> removeHost <host name> 
    zone <name> listHosts 
       The addHost command adds a host with a given name, address 
       and optional aliases to the zone. 

       The removeHost command removes a host from the zone.

       The listHosts command lists the hosts in the zone.

    zone <name> addRR [-staged|-sync] <name> [<ttl>] [<class>] <type> <data>
    zone <name> addDNSRR <name> [<ttl>] <type> <data>
    zone <name> removeRR <name> [<type> [<data>]]
    zone <name> removeDNSRR <name> [<type>] [<data>]
    zone <name> listRR [all|ccm|dns]
    zone <name> findRR [-namePrefix <namePrefix>]
          [-rrTypes <rrTypeList>]  [-protected | -unprotected]

       The addRR command adds a protected resource record to a zone.
       The arguments to addRR are in the same format as BIND files. 
       An attempt to add a protected record to an unprotected name 
       will fail.

       The removeRR command removes all specified protected resource
       records.  Resource records may be specified by name, by name 
       and type, or by name, type, and data (the data is specified in
       BIND-style format.)
    
       The addDNSRR command adds an unprotected resource record. The 
       name, type, and data must be specified. An attempt to add an 
       unprotected record to a protected name will fail.

       The removeDNSRR command removes all specified unprotected 
       resource records.  Resource records may be specified by name,
       by name+type, or name+type+data. The changes take effect 
       immediately; no serverreload is necessary.  If the DNS server
       is not running, the command will fail.

       The listRR command lists the resource records in the zone. 
       CCM records are the records being managed by the CCM server,
       and stored in its database. DNS records are the records that
       the running DNS server is serving to clients.

       The findRR command displays the resource records matching a 
       name prefix, a list of resource record types, and whether 
       protected or not (or either).

       The cleanRR command removes obsolete resource records.  It is
       particularly useful for removing records remaining from zone
       deletion followed by recreation of the same zone. This command 
       is valid only for pre-6.2 clusters.

    zone <name> protect-name|unprotect-name> <name>
       The protect-name/unprotect-name command sets the protection 
       status of the resource records for the name. Protected names
       cannot be updated using DNS update requests.

    zone <name> forceXfer secondary
       The forceXfer command forces a full zone transfer of a 
       secondary zone, regardless of the zone serial number, to
       synchronize DNS data store. If a normal zone transfer is 
       already in progress, the forceXfer command is scheduled 
       immediately after the normal zone transfer finishes. An 
       option for primary zones has not been implemented yet.

    zone <name> chkpt
    zone <name> dumpchkpt
       The chkpt command forces the specified zone name to be the next
       one checkpointed.  If none are currently being checkpointed 
       it is done immediately.  Otherwise, it is done upon completion
       of the current checkpoint.

       The dumpchkpt command interprets an existing checkpoint file 
       and writes its contents to a file in human-readable format.

    zone <name> scavenge
    zone <name> getScavengeStartTime 
       The scavenge command schedules zone scavenging immediately 
       for the given zone regardless of the scavenging interval.

       The getScavengeStartTime command returns the date and time 
       of the next check for stale records, when records might 
       be scavenged.
   
    zone <secondary-zone-name> promote-to-primary
       The promote-to-primary command can be used to promote a 
       secondary zone to a primary zone (for example, if the primary 
       DNS server has had a hardware failure).

    zone <name> applyTemplate <template-name>
       The applyTemplate command applies the specified zone template
       to the zone. All properties configured on the zone template 
       are applied to the zone.

EXAMPLES
    nrcmd> zone example.com. create primary file=host.local
    nrcmd> zone example.com. create primary ns ns-server 

STATUS

SEE ALSO
    zone-template

PROPERTIES
  Attributes:

    checkpoint-interval[103] (AT_RANGETIME, Optional, default: 3h)
        Sets the number of seconds that elapse between saves of zone data.
        When the interval expires, Network Registrar takes a snapshot of
        the zone data and records it in the zone checkpoint database.

    checkpoint-min-interval[111] (AT_RANGETIME, Optional, default: <none>)
        Specifies the minimum amount of time required (in seconds)
        between the time the first checkpoint occurs and the second
        checkpoint starts. This attribute applies only to zones with
        dynamic resource records.

    defttl[37] (AT_RANGETIME, Required, default: 24h)
        Controls the default TTL value used for resource records in this
        zone that do not specify a TTL.

    dist-map[121] (AT_OBJREF, Optional, default: <none>)
        Identifies the zone distribution map associated with the
        specified zone. The zone distribution map describes which
        primary and secondary DNS servers should provide DNS service
        for this zone.

    dynamic[7] (AT_BOOL, Optional, default: true)
        Enables RFC 2136 dynamic updates to the zone. The most typical source
        of these updates is a DHCP server.

    expire[35] (AT_RANGETIME, Optional, default: 1w)
        Sets the number of seconds that a secondary server can continue
        providing zone data without confirming that the data remains current.
        The expire interval must be greater than the refresh interval.

    minttl[36] (AT_RANGETIME, Optional, default: 10m)
        Sets the minimum TTL value displayed in resource records for this
        zone. Records with TTL values lower than the minttl are published
        with this value.

    nameservers[38] (AT_NLIST(AT_DNSNAME), Required, default: <none>)
        Lists the  nameservers for this zone.

    notify[11] (AT_BOOL, Optional, default: <none>)
        Enables notification of other authoritative servers when this
        zone changes.  When set, to either true or false, it overrides the
        global "notify" value for this zone.

    notify-set[12] (AT_NLIST(AT_IPADDR), Optional, default: <none>)
        Lists additional servers to notify of changes to this zone.  All
        servers listed in NS records for the zone, with the exception of
        the server described by the "ns" property of the zone (the mname
        field of the SOA record), receive notifications.
        Servers listed in "notify-list" are also notified.

    ns[31] (AT_DNSNAME, Required, default: <none>)
        Displays the fully-qualified domain name of the primary name server
        for this zone. This host is the original, or primary source, of data
        for this zone.

    nsttl[39] (AT_DNSTTL, Optional, default: <none>)
        Displays the ttl value applied to the NS resource records of
        the zone.

    origin[1] (AT_DNSNAME, Required, default: <none>)
        Displays the fully-qualified name of the zone's root.  The zone name.

    owner[120] (AT_OBJREF, Optional, default: <none>)
        Names the owner of this zone. Use the owner field to group
        similarly owned zones and to limit administrative access.

    person[32] (AT_DNSNAME, Required, default: <none>)
        Displays a domain name specifying the mailbox of the person
        responsible for this zone.  The first label is a user or mail
        alias, the rest of the labels are a mail destination.  A mailbox
        of hostmaster@test.com would be represented as hostmaster.test.com.

    refresh[33] (AT_RANGETIME, Optional, default: 3h)
        Sets the number of seconds that a secondary server waits before
        polling for zone changes and refreshing its zone data.

    region[141] (AT_OBJREF, Optional, default: <none>)
        Associates a region with the specified object.  Use
        the region field to group similarly located zones and
        to limit administrative access.

    restrict-query-acl[129] (AT_AMELST, Optional, default: <none>)
        Specifies the zone access control list (ACL) used to restrict
        the queries that the DNS server for this zone accepts. This list
        can contain host IPs, network addresses, TSIG keys, and (global)
        ACLs.  Only queries from clients defined in the ACL are accepted.
        If unset, the zone inherits the value of the server's
        restrict-query-acl attribute.

    restrict-xfer[6] (AT_BOOL, Optional, default: false)
        Limits sending zone transfers to a specific set of hosts. If
        you restrict zone transfers, use the restrict-xfer-acl attribute
        to specify the access control list that defines which servers
        can perform zone transfers.

    restrict-xfer-acl[125] (AT_AMELST, Optional, default: <none>)
        Identifies the access control list designating who can receive
        zone transfers from this zone.

    retry[34] (AT_RANGETIME, Optional, default: 60m)
        Sets the number of seconds that a secondary server waits before
        it retries polling for changes to zone data or it retries a zone
        transfer that has encountered errors. The retry interval must be
        less than (expire - refresh).

    scvg-enabled[104] (AT_BOOL, Optional, default: false)
        Enables dynamic resource-record scavenging for the zone. This
        attribute removes stale records when clients are
        configured to perform DNS updates but do not delete their
        entries when they're no longer valid. If the DHCP server is used
        to perform updates, it will also delete records when client
        leases expire. Scavenging should not be enabled on these zones.

    scvg-ignore-restart-interval[109] (AT_RANGETIME, Optional, default: <none>)
        Ensures that the server does not reset the scavenging time
        whenever a server restarts. With this attribute set,
        Network Registrar ignores the time between when a server went
        down and the time it restarts. This interval is normally short.
        The value can range from two hours to one day.
        With any time longer than the set time, Network Registrar
        recalculates the scavenging period to allow for record updates
        that cannot take place while the server is stopped. You can also
        set this attribute on a zone, and the value set on the zone
        overrides the server setting. Default is 2h.

    scvg-interval[105] (AT_RANGETIME, Optional, default: <none>)
        Sets the period of time that must elapse before a DNS server
        can remove an out-of-date address (A) record. An A record becomes
        out-of-date once it ages past its initial creation date plus its
        scvg-refresh-interval and scvg-no-refresh-interval. Default is 1w.

    scvg-max-records[112] (AT_RANGEINT(1-10000), Optional, default: <none>)
        Sets the maximum number of records to remove from a zone during
        its scavenging interval.

    scvg-max-records-searched[108] (AT_INT, Optional, default: <none>)
        Sets the maximum number of records to search for out-of-date
        A records. These records are candidates for scavenging.

    scvg-no-refresh-interval[106] (AT_RANGETIME, Optional, default: <none>)
        With scavenging enabled, sets the interval during which DNS
        updates cannot increment an A record timestamp. After both
        the no-refresh and refresh intervals expire, the record becomes a
        candidate for scavenging. The value can range from one hour to
        365 days. You can also set this attribute on a zone, and the
        value set on the zone overrides the server setting. Default is 1w.

    scvg-pause-interval[110] (AT_RANGETIME, Optional, default: <none>)
        Sets the number of seconds the server waits after scavenging
        one set of records before going to the next set.

    scvg-refresh-interval[107] (AT_RANGETIME, Optional, default: <none>)
        With scavenging enabled, sets the interval during which DNS
        updates can increment the A record timestamp. After both the
        no-refresh and refresh intervals expire, the record is a
        candidate for scavenging. The value can range from one hour
        to 365 days. You can also set this  attribute on a zone, and
        the value set on the zone overrides the server setting.
        Default is 1w.

    serial[21] (AT_INT, Required, default: <none>)
        Displays an administratively specified serial number. The serial
        number value must always increase; therefore, this serial number is
        only applied to the zone if it is greater than the actual (dynamic)
        serial number.

    soattl[30] (AT_DNSTTL, Optional, default: <none>)
        Displays the time-to-live (ttl) value applied to the SOA
        resource record of the zone.

    subzone-forward[123] (AT_ENUMINT(), Optional, default: normal)
        Specifies whether subzones use forwarders or not. When no-forward is
        set, any query for the zone is not sent to the forwarder. This
        is an extended resolution exception.

    update-acl[13] (AT_AMELST, Optional, default: <none>)
        Specifies the access control list for DNS updates to the zone,
        given as an address match element list. The access control list
        is not applied to administrative edits managed through the CCM server.

    update-policy-list[134] (AT_NLIST(AT_STRING), Optional, default: <none>)
        Lists the DNS update policies used to authorize or deny DNS
        updates. This attribute is ignored if the update-acl attribute
        is also set.

