Re: Stub zones vs minimal responses

2013-06-12 Thread Tony Finch
Chris Buxton wrote: > > If an authoritative server is configured to send minimal responses, will > a stub zone get all the necessary data from that server? What I'm seeing > is, the recursive server sends an SOA query; the response contains only > the SOA record, and no NS or A records. The recurs

Re: What happens when one out of three NSs are down?

2013-06-12 Thread Matus UHLAR - fantomas
On 11.06.13 20:12, Gary Wallis wrote: What really happens in the real world when 1 out of three authoritative NSs are down for 30 minutes due to a datacenter outage? completely nothing should happen. ns1.someisp.net 12.23.34.45 ns2.someisp.net 23.34.45.56 ns3.someisp.net 34.45.56.67 All in

Re: Stub zones vs minimal responses

2013-06-12 Thread Chris Buxton
On Jun 12, 2013, at 5:23 AM, Tony Finch wrote: > Chris Buxton wrote: >> >> If an authoritative server is configured to send minimal responses, will >> a stub zone get all the necessary data from that server? What I'm seeing >> is, the recursive server sends an SOA query; the response contains on

Re: What happens when one out of three NSs are down?

2013-06-12 Thread Chris Buxton
On Jun 11, 2013, at 4:12 PM, Gary Wallis wrote: > DNS experts: > > What really happens in the real world when 1 out of three authoritative NSs > are down for 30 minutes due to a datacenter outage? > > For example, we have 3 NSs: > > ns1.someisp.net 12.23.34.45 > ns2.someisp.net 23.34.45.56 > n

Re: What happens when one out of three NSs are down?

2013-06-12 Thread WBrown
> From: Chris Buxton > In practice, though, your best bet is to find out why that small > group of customers are having problems. Are they querying the > servers directly? Are they behind the routing problem and can get to the isolated name server and not the other two servers? Confidentia

DNS Amplification Attacks... and a trivial proposal

2013-06-12 Thread Ronald F. Guilmette
I personally have been mad as hell about DNS amplification attacks, ever since I first had the displeasure of finding myself on the business end of one back in 2003. In recent days however I've been given reason to be outraged about them all over again with the news that two organiza- tions that