Skip to Content.
Sympa Menu

netsec-sig - [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?

Subject: Internet2 Network Security SIG

List archive

[Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?


Chronological Thread 
  • From: Jeff Bartig <>
  • To: Dave Diller <>
  • Cc: "" <>, NTAC <>, Kim Milford <>, "" <>
  • Subject: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?
  • Date: Fri, 03 Nov 2017 11:48:14 -0500
  • Authentication-results: maxgigapop.net; dkim=none (message not signed) header.d=none;maxgigapop.net; dmarc=none action=none header.from=internet2.edu;
  • Ironport-phdr: 9a23:rK4I2hTFkHLjRtyT7HxnjMmKrNpsv+yvbD5Q0YIujvd0So/mwa67ZBGOt8tkgFKBZ4jH8fUM07OQ6PGwHzRYqb+681k6OKRWUBEEjchE1ycBO+WiTXPBEfjxciYhF95DXlI2t1uyMExSBdqsLwaK+i764jEdAAjwOhRoLerpBIHSk9631+ev8JHPfglEnjSwbLdxIRmssQndqtQdjJd/JKo21hbHuGZDdf5MxWNvK1KTnhL86dm18ZV+7SleuO8v+tBZX6nicKs2UbJXDDI9M2Ao/8LrrgXMTRGO5nQHTGoblAdDDhXf4xH7WpfxtTb6tvZ41SKHM8D6Uaw4VDK/5KpwVhTmlDkIOCI48GHPi8x/kqRboA66pxdix4LYeZyZOOZicq/Ye94VQndPXttKVyxZHIyzc5cPAeQGPeZdtYb9pl0Opga6CQSjAO7jzzlFjWL006InyeQsCQLI0gIgEd0Av3vassj7NKkQXu+pzanF1i/MY+9M1jjn9ITFaA0trPeRVrxwa8rRzkwvGhvBgFqOp4zlMS6e2/kXvGiB8+pgVO2vgHMgpgFzuTeg3N0sipXIhoIa0V3E9CN5wJorKt2iTk50f8KkHIVKuy6EKoR2X9ovTmd1syg0zb0GvIS0fCkMyJk/3x7QdeKIc5KJ4hLlW+aePCx3iGh5d7K4gha+6Uegyur7Vsm71FZFsDBJncXLtnAI0RHY98uJSuNl80u/wzmDyx3f5+RZLUwpiKbWLpAhz7EsmpYPtEnOHDH5lUrqgKKTc0go5PSk5ur/brn7upOROJV4hh/xP6kggMCzHOs1PwwUU2WU5+ix0qDo81fjT7VQlPI2l7HUsJDEKsQfoa60Gxdb35ok5RqjEjuqyckWk2EaIF5cfxKIlJbmN0vJIPDlEfewmFOskCptx//bJLHhGo/NLn/fkLj/Ybl9909cyA01zdxF4JJUF60BIPb0Wk/2t9zUFAM2Mwuxw+r/CdV90J0RWX6XD6OHKqzerUKE6+cyL+WReYMYvTj9Jvc56/LyiHI0m0EScKa10ZYSbX20AOhqLkuBbXrpmNgBEGMKvgQkTOztjV2PSTxTaG2oUKIm+jE7CY2mAJzCRoCrnLyOwj27HptIaWBaFFyAC2nneJiZW/sUciKdPtdhkiAYVbimU4Ihzg+huxPny7p9L+rU5i0ZuYvt1dh6/ODTkRAy9SdoD8SGzW2BVWB0nmUURzAoxqB/p1Jyykud3aRinfNXCMFT7etTUggmLZ7c0/B6C9fqVwLHYteGUkqpT86iATEwVdIx38QOb1hnF9WjiBDDwzSlA6UTl7OVGJw47LjQ0GbsKMZgmD760/wNhkcrCudOMWmrnOYr+wHNCqbMmlWWlqmjbaMEmijA6DHQ43CJuRR6XQB+GY/MR2weaQOCr97w/F/DQJevD6gqKA1M1ZTEJ6dXPI66xW5aTevubYyNK1m6nH29UFPVn74=
  • Spamdiagnosticoutput: 1:0


On 11/3/17, 10:03 AM, Dave Diller wrote:

MAX had an I2-facing instantiation of D-root for a while last year.  From what I remember, there really was not a lot of traffic to it, as compared to the commodity-facing ones, and they redeployed. 

Kinda makes sense, due to lower visibility in an isolated network, versus worldwide.

But it did not seem to suck in a lot of traffic simply due to query concentration / localpref.

DNS resolvers generally track the response time of root servers and tend to prefer using those that respond the fastest.  Could D-Root via MAX not have gotten a lot of traffic from R&E because there were geographically closer options available?

I took a look at root server routes via the R&E and TR-CPS route tables a few months back as a tangent off a question about .edu TLD server access.  Here is a link to the results:

https://docs.google.com/spreadsheets/d/138pHua9U1tG1S6o08cNJiM3RWsYpUuqqhzRVLMfbDLA/edit?usp=sharing

TR-CPS has pretty good, diverse access to many of the root-servers.  There are improvements that can be made that I need to pursue.

R&E has access to routes to fewer root servers and in many cases those are poor routes.  I've flagged routes that lead to servers outside the U.S. in red on the spreadsheet above.

Since the R&E community often times local-prefs the routes learned from Internet2 and R&E peers higher than other routes, these foreign routes to root servers would be preferred.  If at the same time, DNS resolvers prefer low latency roots, then the U.S. R&E community is basically going to ignore the I, J, K, L, and M root servers because of the high latency routes being provided by Internet2.  My thought on this is providing no route would be better than providing a poor route in these cases.

Jeff

--
Jeff Bartig
Interconnection Architect
Internet2  AS11164 / AS11537
+1-608-616-9908



Archive powered by MHonArc 2.6.19.

Top of Page