Friday | 10 July, 2009
CSO
DNS error brings Sophos antivirus updates to a halt
Optus, Internode and Equinix affected among others.
Darren Pauli (Computerworld) 05/09/2008 13:40:00

UPDATE Sophos has resolved the outage as of 13.30

A sporadic domain name server (DNS) error has blocked Sophos anti-virus updates around the world.

Sophos chief of technology Paul Ducklin said the cause of the error is as yet unknown.

“The update is still working in areas, but there are some dud ISP DNS entries that have Sophos.com listed as off the air which haven't fixed their caches yet,” Ducklin said.

“There was some 'not there' data published by Sophos's ISP in the United Kingdom. Bigpond and Exetel, for example, are working fine.

Experts say the error could be caused by DNS caches which have stored a dodgy update of the Sophos servers, and are feeding them to customers.

The caches collect and store server data for a minimum time, dubbed the Minimum Cache Time to Live (MCTTL), as specified by the sever owners. The data, which could be between 12 and 24 hours old depending on the MCTTL, is fed to ISP customers who request access to the servers. Users can be fed corrupt data during the MCTTL if the caches downloaded errors in the updates.

“It is a transient DNS problem that has been cached and once [the cache] expires, it will start working again it,” Ducklin said

Ducklin also said affected users can still update their software by subscribing to an alternative DNS.

Internode network engineer Mark Newton said the errors could clear once the minimum cache refresh times expire, but added Sophos cannot force an update once the data has been downloaded.

“Caches will nuke the data when the MCTTL expires [but] they will retain the records until the time expires,” Newton said.

“ISPs can manually refresh their DNSes if Sophos wants it to happen.”

Tests conducted by IDG suggest affected DNS servers include those hosted by Optus, Internode and Equinix, among others.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Syndicate content Syndicate content Syndicate content Syndicate content
 
Whitepaper

Look before you leap | Key considerations for moving to 802.11n

Discover how you can plan a high performance 802.11n network and how your business can reap the maximum benefit from a clean-slate 802.11n impementation. Read on to discover the best 802.11n strategy for your organisation.

Sponsored Links