Skip to Content.
Sympa Menu

netsec-sig - [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?

Subject: Internet2 Network Security SIG

List archive

[Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?


Chronological Thread 
  • From: Steven Wallace <>
  • To: Brad Fleming <>
  • Cc: Dave Diller <>, Akbar Kara <>, Bill Owens <>, "" <>, NTAC <>, Kim Milford <>, "" <>
  • Subject: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?
  • Date: Fri, 3 Nov 2017 11:42:26 -0400
  • Ironport-phdr: 9a23:nsSCHhxPSX6bnkPXCy+O+j09IxM/srCxBDY+r6Qd1OMUIJqq85mqBkHD//Il1AaPBtSLraocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze6/9pnQbglSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDtU7s6RSqt4LtqSB/wiScIKTg58H3MisdtiK5XuQ+tqwBjz4LRZoyeKfhwcb7Hfd4CRWRPXdpeWCNcDI2ybYQBEeQBMP1Xr4XholsDtweyCRWuCe7p1zRGhmX23ao/0+k5DA/GwBIvH8wQv3TSsd76NL0dUeSxzKbS0TrMce5d1DDm6IjTfBEsuvCMXa9qfcXP1EYvChrIg1ONooLmJzOYzvkBvmef4uZ6SO6iim4qpxtsrjWhycogkIvEi40Tx1vZ7yt22pw1Kse9SENjYd6rDp9QtyaCOotzWMwiQmVotDwmxb0apZG3ZicKyI4hxx7Yd/OLaYmI4g/5WOmPPDh4mWppeLO5hxms7Uit0vDwW8aw3VpQsyZIk9nBumoQ2xHd5cWLUPlw80i51TaKzQ/T6+VEIU4ularcLp4s2qUwloEdsEnYHy/2hV/6g7GLeUU54uSo8fjoYq36pp+AMI95kgf+Mrg0lcOjGuk4NgkOX3OH+eSnyrHv50z5QLNWjvIoiKnZto7VJdgFqqKjHQBaz5sj4Q6lDzi6yNQYgWUHLFVddRKckYfmJ0zOIOr5Dfejg1WgiTlqx//dM73lA5XNNWTDkKz/cbpn6k5czhYzws5F55JSFL4BPOz/VlXvu9PFEx9qezCzlsz9Adk1+IcTXGOJDefNOq/ctVKN5+QgC+qFYpUYvnD7JuRztND0inpsokMQY6SvlaQebHSxFfkud16CflLtn5EMHXpc7Vl2d/DjlFDXCW0bXH21Ra9po2hjUI8=

Brad,

I’m thinking out loud, so I wouldn't change anything without better advice :-)

steve


On Nov 3, 2017, at 11:35 AM, Brad Fleming <> wrote:


On Nov 3, 2017, at 10:03 AM, Dave Diller <> wrote:



I think we need to be careful WRT to routes to roots. Roots are anycast, and since most of us local-pref TR-CPS/I2, this could lead to suboptimal DNS requests, both in terms of path used, and concentrating queries to fewer serves. This may already be happening. It would be good for someone to check the I2/CPS routing tables for the root anycast prefixes.

MAX had an I2-facing instantiation of D-root for a while last year.  From what I remember, there really was not a lot of traffic to it, as compared to the commodity-facing ones, and they redeployed.

Kinda makes sense, due to lower visibility in an isolated network, versus worldwide.

But it did not seem to suck in a lot of traffic simply due to query concentration / localpref.

-dd


KanREN hosts and announces availability to an L-Root instance running on dedicated hardware in the Kansas City area. We announce:
199.7.82.0/23
199.7.83.0/24
2001:500:3::/48
2001:500:9e::/47 
2001:500:9f::/48
to TR-CPS as well as R&E. They requested we announce the prefixes at all peering points; however, it might make sense for us to withdraw the paths from I2 routing tables simply to avoid the situation Steve points out.

I don’t wanna drag the thread too far off it’s original purpose so feel free to hit me up unicast with any profanity-laden emails about our backwater, hair-brained schemes. :D
--
Brad Fleming
Assistant Director for Technology
Kansas Research and Education Network

Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.19.

Top of Page