nanog mailing list archives

Re: Google public DNS flapping/non-functional


From: Casey Deccio <casey () deccio net>
Date: Thu, 28 Mar 2013 14:22:40 -0700

On Thu, Mar 28, 2013 at 11:51 AM, Blair Trosper <blair.trosper () gmail com>wrote:

Could someone from Google contact me off list to discuss the public
resolvers?

I'm getting NXDOMAIN and then a proper response literally one second later.
 And from there it's just 20 GOTO 10...the resolver seems to be having a
psychotic episode, or...at the very least...an identity crisis.


These symptoms have been seen on DNSSEC validating resolvers when they
encounter a signed zone that is misconfigured.  Google has recently begun
DNSSEC validation, so it could very well be related, depending the
configuration of the zone in question, including whether or not it is
signed, and Google's resolver/validator implementation.

Casey


Current thread: