nanog mailing list archives
EDNS (Re: Are the Servers of Spamhaus.rg and blackholes.us down?)
From: Paul Vixie <vixie () isc org>
Date: Fri, 01 Jan 2010 21:44:13 +0000
Jason Bertoch <jason () i6ix com> writes:
Dec 31 10:12:37 linux-1ij2 named[14306]: too many timeouts resolving 'XXX.YYY.ZZZ/A' (in 'YYY.ZZZ'?): disabling EDNSDo you have a firewall in front of this server that limits DNS packets to 512 bytes?
statistically speaking, yes, most people have that. which is damnfoolery, but well supported by the vendors, who think either that udp/53 datagrams larger than 512 octets are amplification attacks, or that udp packets having no port numbers because they are fragments lacking any udp port information, are evil and dangerous. sadly, noone has yet been fired for buying devices that implement this kind of overspecification. hopefully that will change after the DNS root zone is signed and udp/53 responses start to generally include DNSSEC signatures, pushing most of them way over the 512 octet limit. it's going to be another game of chicken -- will the people who build and/or deploy such crapware lose their jobs, or will ICANN back down from DNSSEC? -- Paul Vixie KI6YSY
Current thread:
- EDNS (Re: Are the Servers of Spamhaus.rg and blackholes.us down?) Paul Vixie (Jan 01)
- Re: EDNS (Re: Are the Servers of Spamhaus.rg and blackholes.us down?) bmanning (Jan 01)
- Re: EDNS (Re: Are the Servers of Spamhaus.rg and blackholes.us down?) Paul Vixie (Jan 01)
- Re: EDNS (Re: Are the Servers of Spamhaus.rg and blackholes.us down?) Eric Brunner-Williams (Jan 01)
- dark fiber and sfp distance limitations Mike (Jan 01)
- Re: dark fiber and sfp distance limitations Justin M. Streiner (Jan 01)
- Re: dark fiber and sfp distance limitations Mikael Abrahamsson (Jan 02)
- Re: dark fiber and sfp distance limitations Michael K. Smith (Jan 02)
- Re: dark fiber and sfp distance limitations Justin M. Streiner (Jan 02)
- Re: dark fiber and sfp distance limitations Nick Hilliard (Jan 02)
- Re: dark fiber and sfp distance limitations Mikael Abrahamsson (Jan 02)
- dark fiber and sfp distance limitations Mike (Jan 01)
- Re: EDNS (Re: Are the Servers of Spamhaus.rg and blackholes.us down?) bmanning (Jan 01)