netsec-sig - [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?
Subject: Internet2 Network Security SIG
List archive
- From: Jeff Bartig <>
- To: Dave Diller <>
- Cc: "" <>, NTAC <>, Kim Milford <>, "" <>
- Subject: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?
- Date: Fri, 03 Nov 2017 11:48:14 -0500
- Authentication-results: maxgigapop.net; dkim=none (message not signed) header.d=none;maxgigapop.net; dmarc=none action=none header.from=internet2.edu;
- Ironport-phdr: 9a23:rK4I2hTFkHLjRtyT7HxnjMmKrNpsv+yvbD5Q0YIujvd0So/mwa67ZBGOt8tkgFKBZ4jH8fUM07OQ6PGwHzRYqb+681k6OKRWUBEEjchE1ycBO+WiTXPBEfjxciYhF95DXlI2t1uyMExSBdqsLwaK+i764jEdAAjwOhRoLerpBIHSk9631+ev8JHPfglEnjSwbLdxIRmssQndqtQdjJd/JKo21hbHuGZDdf5MxWNvK1KTnhL86dm18ZV+7SleuO8v+tBZX6nicKs2UbJXDDI9M2Ao/8LrrgXMTRGO5nQHTGoblAdDDhXf4xH7WpfxtTb6tvZ41SKHM8D6Uaw4VDK/5KpwVhTmlDkIOCI48GHPi8x/kqRboA66pxdix4LYeZyZOOZicq/Ye94VQndPXttKVyxZHIyzc5cPAeQGPeZdtYb9pl0Opga6CQSjAO7jzzlFjWL006InyeQsCQLI0gIgEd0Av3vassj7NKkQXu+pzanF1i/MY+9M1jjn9ITFaA0trPeRVrxwa8rRzkwvGhvBgFqOp4zlMS6e2/kXvGiB8+pgVO2vgHMgpgFzuTeg3N0sipXIhoIa0V3E9CN5wJorKt2iTk50f8KkHIVKuy6EKoR2X9ovTmd1syg0zb0GvIS0fCkMyJk/3x7QdeKIc5KJ4hLlW+aePCx3iGh5d7K4gha+6Uegyur7Vsm71FZFsDBJncXLtnAI0RHY98uJSuNl80u/wzmDyx3f5+RZLUwpiKbWLpAhz7EsmpYPtEnOHDH5lUrqgKKTc0go5PSk5ur/brn7upOROJV4hh/xP6kggMCzHOs1PwwUU2WU5+ix0qDo81fjT7VQlPI2l7HUsJDEKsQfoa60Gxdb35ok5RqjEjuqyckWk2EaIF5cfxKIlJbmN0vJIPDlEfewmFOskCptx//bJLHhGo/NLn/fkLj/Ybl9909cyA01zdxF4JJUF60BIPb0Wk/2t9zUFAM2Mwuxw+r/CdV90J0RWX6XD6OHKqzerUKE6+cyL+WReYMYvTj9Jvc56/LyiHI0m0EScKa10ZYSbX20AOhqLkuBbXrpmNgBEGMKvgQkTOztjV2PSTxTaG2oUKIm+jE7CY2mAJzCRoCrnLyOwj27HptIaWBaFFyAC2nneJiZW/sUciKdPtdhkiAYVbimU4Ihzg+huxPny7p9L+rU5i0ZuYvt1dh6/ODTkRAy9SdoD8SGzW2BVWB0nmUURzAoxqB/p1Jyykud3aRinfNXCMFT7etTUggmLZ7c0/B6C9fqVwLHYteGUkqpT86iATEwVdIx38QOb1hnF9WjiBDDwzSlA6UTl7OVGJw47LjQ0GbsKMZgmD760/wNhkcrCudOMWmrnOYr+wHNCqbMmlWWlqmjbaMEmijA6DHQ43CJuRR6XQB+GY/MR2weaQOCr97w/F/DQJevD6gqKA1M1ZTEJ6dXPI66xW5aTevubYyNK1m6nH29UFPVn74=
- Spamdiagnosticoutput: 1:0
On 11/3/17, 10:03 AM, Dave Diller wrote:
DNS resolvers generally track the response time of root servers and tend to prefer using those that respond the fastest. Could D-Root via MAX not have gotten a lot of traffic from R&E because there were geographically closer options available? I took a look at root server routes via the R&E and TR-CPS route tables a few months back as a tangent off a question about .edu TLD server access. Here is a link to the results: https://docs.google.com/spreadsheets/d/138pHua9U1tG1S6o08cNJiM3RWsYpUuqqhzRVLMfbDLA/edit?usp=sharing TR-CPS has pretty good, diverse access to many of the root-servers. There are improvements that can be made that I need to pursue. R&E has access to routes to fewer root servers and in many cases those are poor routes. I've flagged routes that lead to servers outside the U.S. in red on the spreadsheet above. Since the R&E community often times local-prefs the routes learned from Internet2 and R&E peers higher than other routes, these foreign routes to root servers would be preferred. If at the same time, DNS resolvers prefer low latency roots, then the U.S. R&E community is basically going to ignore the I, J, K, L, and M root servers because of the high latency routes being provided by Internet2. My thought on this is providing no route would be better than providing a poor route in these cases. Jeff |
- [Security-WG] DNS Serving Stale to the rescue?, Steven Wallace, 11/02/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Bill Owens, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Akbar Kara, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Dave Diller, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Brad Fleming, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Brad Fleming, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Jeff Bartig, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Dave Diller, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Paul Howell, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/06/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Paul Howell, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- Message not available
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, John Kristoff, 11/05/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Akbar Kara, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Bill Owens, 11/03/2017
Archive powered by MHonArc 2.6.19.