[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] IP Change



In regard to the DNS TTL our policy is as follows

Our defualt TTL is 24 hours. So when we are planning a change
we will change the TTL on the hosts we are going to change to 5 minutes.

We will then wait 25 hours to make the changes, and then return the TTL
to default. This way nobody (that respects expire times) will have any
longer than a 5 minutes outage due to dns. This has work very well for
us over the years.

Make sure you find out what your TTL is first, follow this example and
you should be just fine. We have moved entire data centers over to new
IP's like this.  

John

-----Original Message-----
From: rpaiz@xxxxxxxxxxxxxx [mailto:rpaiz@xxxxxxxxxxxxxx]
Sent: Tuesday, March 27, 2001 12:30 PM
To: admin@xxxxxxxxxxxxxxxxx
Subject: RE: [cobalt-users] IP Change


> I had a number of sites using the same IP address. As the
> servers main site is now using SSL, I am changing the IP
> addresses for all the other sites.

Just to make sure... you're aware that you can only have one SSL-enabled
site per IP, but that this site *can* share the IP with lots of
non-SSL-enabled sites? The SSL site must be the only SSL-secured site on
the IP, but it doesn't have to be *the only site* on the IP.

> but could I have done anything different?

Yes.

> Would adjusting the time settings in the SOA for the
> sites with the new IPs have helped speed things up any?

Yes. Set the TTL values to something low (like 1 hour) and leave them
that way for several days. Then change the DNS to the new addresses and
return the TTL to a normal value. Hopefully most people respect caching
limits and hopefully many people don't even notice. Those that don't
respect expire times, or those that queried your DNS within the last
hour, will see the site as down until they refresh their DNS.

> Should I reboot the server or perhaps restart the
> server with (RaQ 4)
> /etc/rc.d/init.d/httpd stop
> /etc/rc.d/init.d/httpd start

If you've made any changes to the httpd.conf file, you should restart
the *web* server... not the machine itself.

--
Rodolfo J. Paiz
rpaiz@xxxxxxxxxxxxxx <mailto:rpaiz@xxxxxxxxxxxxxx>


_______________________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To Subscribe or Unsubscribe, please go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users