DNS-SERVER-MIB

MIB Reference — IPNetwork Monitor

All MIBsDNS-SERVER-MIB

Organization: IETF DNS Working Group

Last Updated: 1994-01-28

Category: Web and Application Servers

Description:

Defines managed objects for DNS name server software, allowing SNMP-based access to DNS server configuration, zones, and operational counters.

Imported Objects

From RFC-1213

mib-2

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Gauge32
IpAddress
MODULE-IDENTITY
OBJECT-IDENTITY
OBJECT-TYPE

From SNMPv2-TC

DisplayString
RowStatus
TEXTUAL-CONVENTION
TruthValue

What Is DNS-SERVER-MIB?

DNS-SERVER-MIB is an IETF/IANA-registered standards-based module for monitoring DNS name server software over SNMP, independent of any particular vendor's DNS implementation. It exposes configuration data (recursion support, implementation identity) alongside operational counters covering query handling, such as authoritative and non-authoritative answers, referrals, and errors. In monitoring terms it is primarily a software-status MIB: dnsServConfigUpTime and dnsServConfigResetTime track how long the DNS service has been running and when it was last reset, while the counter objects reveal whether the server is answering queries successfully or generating an abnormal rate of errors or no-data responses, making this module a foundational building block for dns server monitoring across mixed-vendor deployments. It is a self-contained application-management MIB but is often deployed alongside the general NETWORK-SERVICES-MIB (applTable) for broader application-instance tracking. It is deployed on any server running SNMP-instrumented DNS server software (e.g., BIND or similar) in enterprise and service-provider environments.

IPNetwork Monitor allows you to monitor SNMP objects defined in DNS-SERVER-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • DNS server uptime
  • query counters (authoritative/non-authoritative/errors)
  • recursion configuration
  • referral counts
  • counter reset time

Supported Devices

  • vendor-neutral, standards-based MIB, not tied to a specific manufacturer — applies to any DNS server host (e.g., BIND-based servers)

Monitoring Examples

An operator would poll dnsServConfigUpTime to confirm the DNS process hasn't unexpectedly restarted, and watch dnsServCounterErrors and dnsServCounterAuthNoNames over time to detect a rising rate of failed lookups. A sudden spike in dnsServCounterNonAuthNoDatas or dnsServCounterReferrals relative to dnsServCounterAuthAns could indicate zone data problems or misconfigured delegation. dnsServConfigReset could be invoked to reset counters after such an investigation, and dnsServConfigRecurs confirms whether the server is configured to perform recursive resolution.

OIDs
OID symbolicOID numericTypeAccessDescription
dns1.3.6.1.2.1.32The OID assigned to DNS MIB work by the IANA.
dnsServMIB1.3.6.1.2.1.32.1The MIB module for entities implementing the server side of the Domain Name System (DNS) protocol.
dnsServMIBObjects1.3.6.1.2.1.32.1.1
dnsServConfig1.3.6.1.2.1.32.1.1.1
STR dnsServConfigImplementIdent1.3.6.1.2.1.32.1.1.1.1DisplayStringread-onlyThe implementation identification string for the DNS server software in use on the system, for example; `FNS-2.1'
INT dnsServConfigRecurs1.3.6.1.2.1.32.1.1.1.2INTEGERread-writeThis represents the recursion services offered by this name server. The values that can be read or written are: available(1) - performs recursion on requests from clients. restricted(2) - recursion is performed on requests only from certain clients, for example; clients on an access control list. unavailable(3) - recursion is not available.
DNS dnsServConfigUpTime1.3.6.1.2.1.32.1.1.1.3DnsTimeread-onlyIf the server has a persistent state (e.g., a process), this value will be the time elapsed since it started. For software without persistant state, this value will be zero.
DNS dnsServConfigResetTime1.3.6.1.2.1.32.1.1.1.4DnsTimeread-onlyIf the server has a persistent state (e.g., a process) and supports a `reset' operation (e.g., can be told to re-read configuration files), this value will be the time elapsed since the last time the name server was `reset.' For software that does not have persistence or does not support a `reset' operation, this value will be zero.
INT dnsServConfigReset1.3.6.1.2.1.32.1.1.1.5INTEGERread-writeStatus/action object to reinitialize any persistant name server state. When set to reset(2), any persistant name server state (such as a process) is reinitialized as if the name server had just been started. This value will never be returned by a read operation. When read, one of the following values will be returned: other(1) - server in some unknown state; initializing(3) - server (re)initializing; running(4) - server currently running.
dnsServCounter1.3.6.1.2.1.32.1.1.2
C32 dnsServCounterAuthAns1.3.6.1.2.1.32.1.1.2.2Counter32read-onlyNumber of queries which were authoritatively answered.
C32 dnsServCounterAuthNoNames1.3.6.1.2.1.32.1.1.2.3Counter32read-onlyNumber of queries for which `authoritative no such name' responses were made.
C32 dnsServCounterAuthNoDataResps1.3.6.1.2.1.32.1.1.2.4Counter32read-onlyNumber of queries for which `authoritative no such data' (empty answer) responses were made.
C32 dnsServCounterNonAuthDatas1.3.6.1.2.1.32.1.1.2.5Counter32read-onlyNumber of queries which were non-authoritatively answered (cached data).
C32 dnsServCounterNonAuthNoDatas1.3.6.1.2.1.32.1.1.2.6Counter32read-onlyNumber of queries which were non-authoritatively answered with no data (empty answer).
C32 dnsServCounterReferrals1.3.6.1.2.1.32.1.1.2.7Counter32read-onlyNumber of requests that were referred to other servers.
C32 dnsServCounterErrors1.3.6.1.2.1.32.1.1.2.8Counter32read-onlyNumber of requests the server has processed that were answered with errors (RCODE values other than 0 and 3).
C32 dnsServCounterRelNames1.3.6.1.2.1.32.1.1.2.9Counter32read-onlyNumber of requests received by the server for names that are only 1 label long (text form - no internal dots).
C32 dnsServCounterReqRefusals1.3.6.1.2.1.32.1.1.2.10Counter32read-onlyNumber of DNS requests refused by the server.
C32 dnsServCounterReqUnparses1.3.6.1.2.1.32.1.1.2.11Counter32read-onlyNumber of requests received which were unparseable.
C32 dnsServCounterOtherErrors1.3.6.1.2.1.32.1.1.2.12Counter32read-onlyNumber of requests which were aborted for other (local) server errors.
dnsServCounterTable1.3.6.1.2.1.32.1.1.2.13not-accessibleCounter information broken down by DNS class and type.
dnsServCounterEntry1.3.6.1.2.1.32.1.1.2.13.1not-accessibleThis table contains count information for each DNS class and type value known to the server. The index allows management software to to create indices to the table to get the specific information desired, e.g., number of queries over UDP for records with type value `A' which came to this server. In order to prevent an uncontrolled expansion of rows in the table; if dnsServCounterRequests is 0 and dnsServCounterResponses is 0, then the row does not exist and `no such' is returned when the agent is queried for such instances.
DNS dnsServCounterOpCode1.3.6.1.2.1.32.1.1.2.13.1.1DnsOpCodenot-accessibleThe DNS OPCODE being counted in this row of the table.
DNS dnsServCounterQClass1.3.6.1.2.1.32.1.1.2.13.1.2DnsClassnot-accessibleThe class of record being counted in this row of the table.
DNS dnsServCounterQType1.3.6.1.2.1.32.1.1.2.13.1.3DnsTypenot-accessibleThe type of record which is being counted in this row in the table.
INT dnsServCounterTransport1.3.6.1.2.1.32.1.1.2.13.1.4INTEGERnot-accessibleA value of udp(1) indicates that the queries reported on this row were sent using UDP. A value of tcp(2) indicates that the queries reported on this row were sent using TCP. A value of other(3) indicates that the queries reported on this row were sent using a transport that was neither TCP nor UDP.
C32 dnsServCounterRequests1.3.6.1.2.1.32.1.1.2.13.1.5Counter32read-onlyNumber of requests (queries) that have been recorded in this row of the table.
C32 dnsServCounterResponses1.3.6.1.2.1.32.1.1.2.13.1.6Counter32read-onlyNumber of responses made by the server since initialization for the kind of query identified on this row of the table.
dnsServOptCounter1.3.6.1.2.1.32.1.1.3
C32 dnsServOptCounterSelfAuthAns1.3.6.1.2.1.32.1.1.3.1Counter32read-onlyNumber of requests the server has processed which originated from a resolver on the same host for which there has been an authoritative answer.
C32 dnsServOptCounterSelfAuthNoNames1.3.6.1.2.1.32.1.1.3.2Counter32read-onlyNumber of requests the server has processed which originated from a resolver on the same host for which there has been an authoritative no such name answer given.
C32 dnsServOptCounterSelfAuthNoDataResps1.3.6.1.2.1.32.1.1.3.3Counter32read-onlyNumber of requests the server has processed which originated from a resolver on the same host for which there has been an authoritative no such data answer (empty answer) made.
C32 dnsServOptCounterSelfNonAuthDatas1.3.6.1.2.1.32.1.1.3.4Counter32read-onlyNumber of requests the server has processed which originated from a resolver on the same host for which a non-authoritative answer (cached data) was made.
C32 dnsServOptCounterSelfNonAuthNoDatas1.3.6.1.2.1.32.1.1.3.5Counter32read-onlyNumber of requests the server has processed which originated from a resolver on the same host for which a `non-authoritative, no such data' response was made (empty answer).
C32 dnsServOptCounterSelfReferrals1.3.6.1.2.1.32.1.1.3.6Counter32read-onlyNumber of queries the server has processed which originated from a resolver on the same host and were referred to other servers.
C32 dnsServOptCounterSelfErrors1.3.6.1.2.1.32.1.1.3.7Counter32read-onlyNumber of requests the server has processed which originated from a resolver on the same host which have been answered with errors (RCODEs other than 0 and 3).
C32 dnsServOptCounterSelfRelNames1.3.6.1.2.1.32.1.1.3.8Counter32read-onlyNumber of requests received for names that are only 1 label long (text form - no internal dots) the server has processed which originated from a resolver on the same host.
C32 dnsServOptCounterSelfReqRefusals1.3.6.1.2.1.32.1.1.3.9Counter32read-onlyNumber of DNS requests refused by the server which originated from a resolver on the same host.
C32 dnsServOptCounterSelfReqUnparses1.3.6.1.2.1.32.1.1.3.10Counter32read-onlyNumber of requests received which were unparseable and which originated from a resolver on the same host.
C32 dnsServOptCounterSelfOtherErrors1.3.6.1.2.1.32.1.1.3.11Counter32read-onlyNumber of requests which were aborted for other (local) server errors and which originated on the same host.
C32 dnsServOptCounterFriendsAuthAns1.3.6.1.2.1.32.1.1.3.12Counter32read-onlyNumber of queries originating from friends which were authoritatively answered. The definition of friends is a locally defined matter.
C32 dnsServOptCounterFriendsAuthNoNames1.3.6.1.2.1.32.1.1.3.13Counter32read-onlyNumber of queries originating from friends, for which authoritative `no such name' responses were made. The definition of friends is a locally defined matter.
C32 dnsServOptCounterFriendsAuthNoDataResps1.3.6.1.2.1.32.1.1.3.14Counter32read-onlyNumber of queries originating from friends for which authoritative no such data (empty answer) responses were made. The definition of friends is a locally defined matter.
C32 dnsServOptCounterFriendsNonAuthDatas1.3.6.1.2.1.32.1.1.3.15Counter32read-onlyNumber of queries originating from friends which were non-authoritatively answered (cached data). The definition of friends is a locally defined matter.
C32 dnsServOptCounterFriendsNonAuthNoDatas1.3.6.1.2.1.32.1.1.3.16Counter32read-onlyNumber of queries originating from friends which were non-authoritatively answered with no such data (empty answer).
C32 dnsServOptCounterFriendsReferrals1.3.6.1.2.1.32.1.1.3.17Counter32read-onlyNumber of requests which originated from friends that were referred to other servers. The definition of friends is a locally defined matter.
C32 dnsServOptCounterFriendsErrors1.3.6.1.2.1.32.1.1.3.18Counter32read-onlyNumber of requests the server has processed which originated from friends and were answered with errors (RCODE values other than 0 and 3). The definition of friends is a locally defined matter.
C32 dnsServOptCounterFriendsRelNames1.3.6.1.2.1.32.1.1.3.19Counter32read-onlyNumber of requests received for names from friends that are only 1 label long (text form - no internal dots) the server has processed.
C32 dnsServOptCounterFriendsReqRefusals1.3.6.1.2.1.32.1.1.3.20Counter32read-onlyNumber of DNS requests refused by the server which were received from `friends'.
C32 dnsServOptCounterFriendsReqUnparses1.3.6.1.2.1.32.1.1.3.21Counter32read-onlyNumber of requests received which were unparseable and which originated from `friends'.
C32 dnsServOptCounterFriendsOtherErrors1.3.6.1.2.1.32.1.1.3.22Counter32read-onlyNumber of requests which were aborted for other (local) server errors and which originated from `friends'.
dnsServZone1.3.6.1.2.1.32.1.1.4
dnsServZoneTable1.3.6.1.2.1.32.1.1.4.1not-accessibleTable of zones for which this name server provides information. Each of the zones may be loaded from stable storage via an implementation-specific mechanism or may be obtained from another name server via a zone transfer. If name server doesn't load any zones, this table is empty.
dnsServZoneEntry1.3.6.1.2.1.32.1.1.4.1.1not-accessibleAn entry in the name server zone table. New rows may be added either via SNMP or by the name server itself.
DNS dnsServZoneName1.3.6.1.2.1.32.1.1.4.1.1.1DnsNameAsIndexnot-accessibleDNS name of the zone described by this row of the table. This is the owner name of the SOA RR that defines the top of the zone. This is name is in uppercase: characters 'a' through 'z' are mapped to 'A' through 'Z' in order to make the lexical ordering useful.
DNS dnsServZoneClass1.3.6.1.2.1.32.1.1.4.1.1.2DnsClassnot-accessibleDNS class of the RRs in this zone.
DNS dnsServZoneLastReloadSuccess1.3.6.1.2.1.32.1.1.4.1.1.3DnsTimeread-onlyElapsed time in seconds since last successful reload of this zone.
DNS dnsServZoneLastReloadAttempt1.3.6.1.2.1.32.1.1.4.1.1.4DnsTimeread-onlyElapsed time in seconds since last attempted reload of this zone.
IP dnsServZoneLastSourceAttempt1.3.6.1.2.1.32.1.1.4.1.1.5IpAddressread-onlyIP address of host from which most recent zone transfer of this zone was attempted. This value should match the value of dnsServZoneSourceSuccess if the attempt was succcessful. If zone transfer has not been attempted within the memory of this name server, this value should be 0.0.0.0.
ROW dnsServZoneStatus1.3.6.1.2.1.32.1.1.4.1.1.6RowStatusread-createThe status of the information represented in this row of the table.
C32 dnsServZoneSerial1.3.6.1.2.1.32.1.1.4.1.1.7Counter32read-onlyZone serial number (from the SOA RR) of the zone represented by this row of the table. If the zone has not been successfully loaded within the memory of this name server, the value of this variable is zero.
T/F dnsServZoneCurrent1.3.6.1.2.1.32.1.1.4.1.1.8TruthValueread-onlyWhether the server's copy of the zone represented by this row of the table is currently valid. If the zone has never been successfully loaded or has expired since it was last succesfully loaded, this variable will have the value false(2), otherwise this variable will have the value true(1).
IP dnsServZoneLastSourceSuccess1.3.6.1.2.1.32.1.1.4.1.1.9IpAddressread-onlyIP address of host which was the source of the most recent successful zone transfer for this zone. If unknown (e.g., zone has never been successfully transfered) or irrelevant (e.g., zone was loaded from stable storage), this value should be 0.0.0.0.
dnsServZoneSrcTable1.3.6.1.2.1.32.1.1.4.2not-accessibleThis table is a list of IP addresses from which the server will attempt to load zone information using DNS zone transfer operations. A reload may occur due to SNMP operations that create a row in dnsServZoneTable or a SET to object dnsServZoneReload. This table is only used when the zone is loaded via zone transfer.
dnsServZoneSrcEntry1.3.6.1.2.1.32.1.1.4.2.1not-accessibleAn entry in the name server zone source table.
DNS dnsServZoneSrcName1.3.6.1.2.1.32.1.1.4.2.1.1DnsNameAsIndexnot-accessibleDNS name of the zone to which this entry applies.
DNS dnsServZoneSrcClass1.3.6.1.2.1.32.1.1.4.2.1.2DnsClassnot-accessibleDNS class of zone to which this entry applies.
IP dnsServZoneSrcAddr1.3.6.1.2.1.32.1.1.4.2.1.3IpAddressnot-accessibleIP address of name server host from which this zone might be obtainable.
ROW dnsServZoneSrcStatus1.3.6.1.2.1.32.1.1.4.2.1.4RowStatusread-createThe status of the information represented in this row of the table.
dnsServMIBGroups1.3.6.1.2.1.32.1.2
dnsServConfigGroup1.3.6.1.2.1.32.1.2.1A collection of objects providing basic configuration control of a DNS name server.
dnsServCounterGroup1.3.6.1.2.1.32.1.2.2A collection of objects providing basic instrumentation of a DNS name server.
dnsServOptCounterGroup1.3.6.1.2.1.32.1.2.3A collection of objects providing extended instrumentation of a DNS name server.
dnsServZoneGroup1.3.6.1.2.1.32.1.2.4A collection of objects providing configuration control of a DNS name server which loads authoritative zones.
dnsServMIBCompliances1.3.6.1.2.1.32.1.3
dnsServMIBCompliance1.3.6.1.2.1.32.1.3.1The compliance statement for agents implementing the DNS name server MIB extensions.

FAQ

How would DNS-SERVER-MIB help me confirm a BIND server has been stable and answering queries correctly?
dnsServConfigUpTime and dnsServConfigResetTime show how long the DNS service has been running and when it was last reset, while the counter objects for authoritative/non-authoritative answers, referrals, and errors reveal whether the server is answering successfully or generating an abnormal rate of errors.

Can DNS-SERVER-MIB tell me if a name server is misconfigured for recursion?
Yes, it exposes recursion-support configuration alongside implementation identity, so polling those objects confirms whether recursion is enabled as expected on a given DNS server instance.

RFC description

DNS server management MIB for Domain Name System server monitoring.

Start monitoring DNS server host software, e.g. BIND (vendor-neutral, IETF/IANA standard) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download DNS-SERVER-MIB