nanog mailing list archives
Re: Open Resolver Problems
From: Joe Abley <jabley () hopcount ca>
Date: Wed, 27 Mar 2013 09:54:57 -0400
On 2013-03-27, at 09:47, William Herrin <bill () herrin us> wrote:
On Tue, Mar 26, 2013 at 10:07 PM, Tom Paseka <tom () cloudflare com> wrote:Authoritative DNS servers need to implement rate limiting. (a client shouldn't query you twice for the same thing within its TTL).Right now that's a complaint for the mainstream software authors, not for the system operators. When the version of Bind in Debian Stable implements this feature, I'll surely turn it on.
RRL is a moving target, although a promising one. There are currently three implementations of RRL which all behave slightly differently. There is active discussion between the vendors who have implemented RRL, and between early adopters and the vendors. The specification is not yet stable, and changes in the functionality and the rate-limiting behaviour continue to be made. My assessment is that the implementations I have seen are ready for production use, but I think it's understandable given the moving goalpoasts that some vendors have not yet promoted the code to be included in stable releases. As an operator, I understand the benefits of using packaged, stable releases of code. However, we also have a responsibility to deal with operational problems in a timely way. I think it's worth considering that it may well be worth deviating from internal policies about code deployment in this instance; the benefits of doing so can be substantial, and the costs of doing so (especially if we expect them to be time-limited) are not that high. Joe
Current thread:
- Re: Open Resolver Problems, (continued)
- Re: Open Resolver Problems Tom Paseka (Mar 26)
- Re: Open Resolver Problems Matthew Petach (Mar 26)
- Re: Open Resolver Problems Jon Lewis (Mar 26)
- Re: Open Resolver Problems Paul Ferguson (Mar 26)
- Re: Open Resolver Problems Alain Hebert (Mar 27)
- Re: Open Resolver Problems Jared Mauch (Mar 26)
- Re: Open Resolver Problems Mark Andrews (Mar 26)
- Re: Open Resolver Problems Paul Ferguson (Mar 26)
- Re: Open Resolver Problems Mark Andrews (Mar 26)
- Re: Open Resolver Problems William Herrin (Mar 27)
- Re: Open Resolver Problems Joe Abley (Mar 27)
- Re: Open Resolver Problems Tony Finch (Mar 27)
- Re: Open Resolver Problems Jack Bates (Mar 27)
- Re: Open Resolver Problems William Herrin (Mar 27)
- Re: Open Resolver Problems Jack Bates (Mar 27)
- Re: Open Resolver Problems Mark Andrews (Mar 27)
- Re: Open Resolver Problems Tony Finch (Mar 27)
- Re: Open Resolver Problems Jack Bates (Mar 27)
- Re: Open Resolver Problems Tony Finch (Mar 27)
- Re: Open Resolver Problems Joe Abley (Mar 27)
- Re: Open Resolver Problems Valdis . Kletnieks (Mar 27)