nanog mailing list archives

Re: Dyn DDoS this AM?


From: joel jaeggli <joelja () bogus com>
Date: Fri, 21 Oct 2016 16:04:41 -0700

On 10/21/16 3:21 PM, David Birdsong wrote:
On Fri, Oct 21, 2016 at 2:58 PM, Randy Bush <randy () psg com> wrote:

anyone who relies on a single dns provider is just asking for stuff such
as this.

randy

I'd love to hear how others are handling the overhead of managing two dns
providers. Every time we brainstorm on it, we see it as blackhole of eng
effort WRT to keeping them in sync and and then waiting for TTLs to cut an
entire delegation over.

Not all the ones you might choose based on scale support axfr... That's
a bit of a problem for the most traditional approach to this., of those 
that do it's straight-forward to use one as the master for another, or
use a hidden master. Your own master may have demonstrably lower
availability then one or the other of your providers. getting two well
considered choices to play nice with each other isn't that hard.



Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: