netsec-sig - [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?
Subject: Internet2 Network Security SIG
List archive
- From: Steven Wallace <>
- To: Akbar Kara <>
- Cc: Bill Owens <>, "" <>, NTAC <>, Kim Milford <>, "" <>
- Subject: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?
- Date: Fri, 3 Nov 2017 10:54:08 -0400
- Ironport-phdr: 9a23:JMXmlxN2BBgPQ9oUGdsl6mtUPXoX/o7sNwtQ0KIMzox0Iv78rarrMEGX3/hxlliBBdydsKMUzbKO+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZPebgFLiTanfb9+MAi9oBnMuMURnYZsMLs6xAHTontPdeRWxGdoKkyWkh3h+Mq+/4Nt/jpJtf45+MFOTav1f6IjTbxFFzsmKHw65NfqtRbYUwSC4GYXX3gMnRpJBwjF6wz6Xov0vyDnuOdxxDWWMMvrRr0vRz+s87lkRwPpiCcfNj427mfXitBrjKlGpB6tvgFzz5LIbI2QMvd1Y6HTcs4ARWdZXshfVDBODYyhYYUBDeUPI+hYopLyp1cSqBuzHxWgCP/txzJOm3T43bc60+MkEQzewQIgA8wBsGrKo9XzKawdUfq6zK3MzTrZc/xZxyr25Y/TchA6r/CBRrNwcdfLxUYxCgzFk0ydpIr4ND2b0eQNtnKU7+tmVe+3im4otR1xoja1yscrkInJiYQYwU3H+yVh2Is5ONK1RUphbdK5EZZdtzuWO5Z4T84tWW1luik3x7sbspChZicK0o4oxxvHZvyHbYeI5hXjWf6UIThihXJlfKiziAqu8Ue80OH8WdO00FBNriVZiNXMt20N2wbN5ceaV/tx5kah2TCR2ADP8uxIPE85mK7BJ5I8w7M9loAfvVnNEyL5gkn7jqCbel0h+uey6uTnZrvmpoWbN49xkgz+Kb8um8KkDOQ5LwgCRXaU9vmh1LH75032XK1KjuEqkqneqJ3aI9gbqbSlDAJO1oYj6g2/Dyu90NgGh3UHLVRFeA6ZgIjzPVHBPuz4Aemlj1uyjThr2ujMPqf9DZXVMnjDjLDhcK5m60FC1AUz0Mpf55NICrABOf7yVEDxucfcDh84KAy03/3nBMtn2oMfX2KPHrGWMLnUsVCW+uIjPfOAa5EItzbgeLAZ4KvHjnUwgxc+dLOglc8ea3qxBLJlKl+QSWb8x9MMGH0M+AwzULq5pkeFVGtoe3usUqR02Tg/DIutAM+XXZuyqL2cmiq3A8sFNSh9FlmQHCKwJM2/UPAWZXfXe5c5nw==
My scenario is loss of Internet connectivity. That would include loss of TR-CPS. I think we need to be careful WRT to routes to roots. Roots are anycast, and since most of us local-pref TR-CPS/I2, this could lead to suboptimal DNS requests, both in terms of path used, and concentrating queries to fewer serves. This may already be happening. It would be good for someone to check the I2/CPS routing tables for the root anycast prefixes. steve
|
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Security-WG] DNS Serving Stale to the rescue?, Steven Wallace, 11/02/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Bill Owens, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Akbar Kara, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Dave Diller, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Brad Fleming, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Brad Fleming, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Jeff Bartig, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Dave Diller, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Paul Howell, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/06/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Paul Howell, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Akbar Kara, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Bill Owens, 11/03/2017
Archive powered by MHonArc 2.6.19.