nanog mailing list archives

Re: DNS pulling BGP routes?


From: William Herrin <bill () herrin us>
Date: Thu, 7 Oct 2021 13:30:14 -0700

On Thu, Oct 7, 2021 at 10:23 AM Masataka Ohta
<mohta () necom830 hpcl titech ac jp> wrote:
William Herrin wrote:
Facebook's _internal_ DNS, while not anycasted, followed a similar
logic: if the data center is isolated and their data goes stale, they
stop serving potentially wrong answers.

As I already wrote, that is a standard mechanism of DNS with SOA
expiration period as is documented in rfc1034

Then we agree: The failure mode was that after the data centers
disconnected from each other, all their DNS expired, breaking the
tools they'd normally use to recover. Facebook withdrawing the BGP
routes to its anycasted public DNS servers as they expired made no
difference.

Regards,
Bill Herrin

-- 
William Herrin
bill () herrin us
https://bill.herrin.us/


Current thread: