# Bind ver 9.16 in Rocky Linux

**URL:** <https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958>\
**Category:** Rocky Linux Help & Support\
**Created:** [March 20, 2025, 4:44am UTC](https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958 "2025-03-20T04:44:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![padma](https://avatars.discourse-cdn.com/v4/letter/p/ecc23a/32.png) [@padma](https://forums.rockylinux.org/u/padma)\
**Post date:** [March 20, 2025, 4:44am UTC](https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958/1 "2025-03-20T04:44:51Z")

</div>

In bind ver 9.16 in rocky linux . I get the below messages in logs. Could anyone suggest what could be the issue.

`FORMERR resolving 'sin3-ib.sin1.geoadnxs.com/AAAA/IN': 64.208.141.10#53`

Thanks in advance

---

<div class="post-metadata">

**Author:** ![nebraskacoder](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/nebraskacoder/32/5188_2.png) [@nebraskacoder](https://forums.rockylinux.org/u/nebraskacoder)\
**Post date:** [March 20, 2025, 10:39am UTC](https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958/2 "2025-03-20T10:39:48Z")

</div>

Hello, @padma. Is the only server you are seeing this for `64.208.141.10`?

Modern BIND servers often send queries using EDNS (Extension mechanisms for DNS) to allow for larger messages and extra features. Some older or misconfigured DNS servers do not understand these EDNS extensions and will reply with FORMERR when they see them.

If I had to guess, most likely the remote server isn’t fully compatible with EDNS0, so when BIND sends an EDNS-enabled AAAA query (IPv6), the server responds with a format error.

If you’re trying to clean up your logs, you can surpress the errors by disabling EDNS for that specific server so that BIND sends “plain” DNS queries that the server understands. If you want to do this, you add the following to your BIND configuration:

```conf
server 64.208.141.10 {
    edns no;
};

```

In many cases, the resolution falls back (e.g., via A records for IPv4), and you might not have to do anything if you do not see the name resolution affected. This configuration change is for when you want to clean up your logs or ensure proper handling.

Others can chime in if I’m missing the mark on this (since this is based on research I did) or if there is more to add.

---

<div class="post-metadata">

**Author:** ![padma](https://avatars.discourse-cdn.com/v4/letter/p/ecc23a/32.png) [@padma](https://forums.rockylinux.org/u/padma)\
**Post date:** [March 20, 2025, 12:47pm UTC](https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958/3 "2025-03-20T12:47:21Z")

</div>

> [@nebraskacoder](#):
>
> EDNS0, so when BIND sends an EDNS-enabled AAAA query (IPv6), the server responds with a format error.

Hi, @nebraskacoder

Thanks for quick reply. I see the below messages .

Mar 20 18:18:42 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.197.128#53  
Mar 20 18:18:42 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.195.61#53  
Mar 20 18:18:42 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.193.130#53  
Mar 20 18:18:42 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.198.24#53  
Mar 20 18:18:55 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.195.61#53  
Mar 20 18:18:55 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.197.128#53  
Mar 20 18:18:55 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.193.130#53  
Mar 20 18:18:55 intdns named[54354]: FORMERR resolving ‘[trace.mediago.io/HTTPS/IN](http://trace.mediago.io/HTTPS/IN)’: 205.251.198.24#53

Is it possible to resolve or do we need to suppress these messages.

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [March 20, 2025, 4:25pm UTC](https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958/4 "2025-03-20T16:25:07Z")

</div>

If you’re getting FORMERR regardless of the domain, is there something intercepting your DNS traffic? Do you have caching servers? How is your internal DNS actually setup?

---

<div class="post-metadata">

**Author:** ![padma](https://avatars.discourse-cdn.com/v4/letter/p/ecc23a/32.png) [@padma](https://forums.rockylinux.org/u/padma)\
**Post date:** [March 21, 2025, 4:35am UTC](https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958/5 "2025-03-21T04:35:29Z")

</div>

Hi @label,

Thanks for reply. No we do not have caching server. Please find the conf file below. Zone file has been configured but removed below.

options {  
listen-on port 53 { 127.0.0.1; 192.168.xx.xx; };  
// listen-on-v6 port 53 { ::1; };  
directory “/var/named”;  
dump-file “/var/named/data/cache\_dump.db”;  
statistics-file “/var/named/data/named\_stats.txt”;  
memstatistics-file “/var/named/data/named\_mem\_stats.txt”;  
secroots-file “/var/named/data/named.secroots”;  
recursing-file “/var/named/data/named.recursing”;

# allow-query { localhost; };

```
    allow-query { any; };
    tcp-clients 10000;
    recursive-clients 10000;

```

# allow-recursion { localhost; 192.168.xx.xx; };

```
    /*
     - If you are building an AUTHORITATIVE DNS server, do NOT enable recurs ion.
     - If you are building a RECURSIVE (caching) DNS server, you need to ena ble
       recursion.
     - If your recursive DNS server has a public IP address, you MUST enable access
       control to limit queries to your legitimate users. Failing to do so w ill
       cause your server to become part of large scale DNS amplification
       attacks. Implementing BCP38 within your network would greatly
       reduce such attack surface
    */

```

# recursion yes;

```
    dnssec-validation no;

    managed-keys-directory "/var/named/dynamic";
    geoip-directory "/usr/share/GeoIP";

    pid-file "/run/named/named.pid";
    session-keyfile "/run/named/session.key";

    /* https://fedoraproject.org/wiki/Changes/CryptoPolicy */
    include "/etc/crypto-policies/back-ends/bind.config";

```

};

logging {  
channel default\_debug {  
file “data/named.run”;  
severity dynamic;  
};

};

server ::/0 {  
edns no;  
};  
server 0.0.0.0/0 {  
edns no;  
};

//zone file has been mentioned

#include “/etc/named.rfc1912.zones”;  
#include “/etc/named.root.key”;

Log generated daily are in 3 to 4 MB.

Hi @nebraskacoder,

Name resolution is happening. There is no issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [May 20, 2025, 4:46am UTC](https://forums.rockylinux.org/t/bind-ver-9-16-in-rocky-linux/17958/7 "2025-05-20T04:46:06Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
