Re: Deprecated DSCP support

2024-02-29 Thread Stacey Marshall
Not familiar with DSCP, Differentiated Services Code Point, a means of classifying and managing network traffic and of providing quality of service (QoS) in modern IP networks [D]. Google search found me a libuv conversation `Setting DSCP per UDP datagram` [A] which links to `Extending the u

Re: Deprecated DSCP support

2024-02-29 Thread Wolfgang Riedel via bind-users
Hi Folks, OK let me help you a bit as it’s really essential for DNS traffic which need to be go through in all situations!!! Within the OS networking stack as also within the network there is always a prioritisation of packets within the queues to serialise the packets of an application to go

Re: Deprecated DSCP support

2024-02-29 Thread Petr Špaček
On 28. 02. 24 13:50, Balazs Hinel (Nokia) via bind-users wrote: I am working on a product in Nokia, and we currently use BIND provided by Rocky Linux 8 with security patches. Recently the requirement came that we should upgrade to at least 9.16. During the testing of this version we realized th

Re: Deprecated DSCP support

2024-02-29 Thread Petr Menšík
What I do not understand is, why is not matching always port 53 either on source ports or destination ports as enough to set dscp marks. Unless you need to differentiate dscp based on domain names, used views or something similar, iptables rules should be able to set dscp very similar way. With

Re: Deprecated DSCP support

2024-02-29 Thread Ondřej Surý
How does that actually help with anything? The DNS traffic is not one way, but two way and unless everyone is setting DSCP on the DNS messages the incoming DNS messages will have same priority as incoming FTP traffic (to use your example).Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your

Re: Deprecated DSCP support

2024-02-29 Thread Greg Choules via bind-users
Hi Wolfgang. Firstly let me say that I have never been a fan of QoS. So I'm slightly biased against the whole thing in the first place. But regarding your comment "It’s not easy for the network to guess the requirements of an application," I would disagree. Traffic classification and setting of DS

Re: Deprecated DSCP support

2024-02-29 Thread Borja Marcos
> On 29 Feb 2024, at 10:21, Petr Špaček wrote: > > On 28. 02. 24 13:50, Balazs Hinel (Nokia) via bind-users wrote: >> I am working on a product in Nokia, and we currently use BIND provided by >> Rocky Linux 8 with security patches. Recently the requirement came that we >> should upgrade to at

Re: Deprecated DSCP support

2024-02-29 Thread G.W. Haywood
Hi there, On Thu, 29 Feb 2024, Wolfgang Riedel wrote: In my case it?s dscp 24 in named.conf ... If you don't set it, ... ns9:~# >>> man named.conf | grep dscp dscp ; // obsolete -- 73, Ged. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this

Re: Deprecated DSCP support

2024-02-29 Thread Robert Franklin
Hello, > On 29 Feb 2024, at 09:34, Greg Choules via bind-users > wrote: > > But regarding your comment "It’s not easy for the network to guess the > requirements of an application," I would disagree. Traffic classification and > setting of DSCP values is something that edge routers have been

occasional SERVFAIL error

2024-02-29 Thread Ludovit Koren
Hi, occasionally I get the following SERVFAIL error: dig www.jiscd.sk ; <<>> DiG 9.18.24 <<>> www.jiscd.sk ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 12207 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTI

Re: occasional SERVFAIL error

2024-02-29 Thread Peter Davies
Hi Ludovit,    It looks like you have two version of the jiscd.sk zone. host -C jiscd.sk Nameserver 2001:67c:1bd4:8080::20:     jiscd.sk has SOA record ns1.gov.sk. gov.sk. 2024022501 7200 3600 604800 86400 Nameserver 195.49.191.160:     jiscd.sk has SOA record ns1.gov.sk. gov.sk. 2024022501 72

fixed rrset ordering - is this still a thing?

2024-02-29 Thread Ondřej Surý
Hey, BIND 9 supports a fixed rrset ordering (that is keeping the order of the RRSets from the zone file). It has to be configured at the compile time, it takes more memory (to record that order) and it's a #ifdef all over the places. So, henceforth, my question - does anyone still uses that? An

Re: fixed rrset ordering - is this still a thing?

2024-02-29 Thread Matt Nordhoff via bind-users
On Thu, Feb 29, 2024 at 9:40 PM Ondřej Surý wrote: > Hey, > > BIND 9 supports a fixed rrset ordering (that is keeping the order of the > RRSets from the zone file). It has to be configured > at the compile time, it takes more memory (to record that order) and it's a > #ifdef all over the places.

Re: fixed rrset ordering - is this still a thing?

2024-02-29 Thread Matt Nordhoff via bind-users
On Fri, Mar 1, 2024 at 12:38 AM Matt Nordhoff wrote: > On Thu, Feb 29, 2024 at 9:40 PM Ondřej Surý wrote: > > Hey, > > > > BIND 9 supports a fixed rrset ordering (that is keeping the order of the > > RRSets from the zone file). It has to be configured > > at the compile time, it takes more memor

Re: Deprecated DSCP support

2024-02-29 Thread Evan Hunt
On Thu, Feb 29, 2024 at 10:34:42AM +0100, Borja Marcos wrote: > But bear in mind that this is only guaranteed to work inside your > network/ASN. It’s not unusual to scrub DSCP at the network border. Same problem would also apply to DSCP values set internally by named, of course. -- Evan Hunt --

Re: Problem upgrading to 9.18 - important feature being removed

2024-02-29 Thread Ondřej Surý
> On 26. 2. 2024, at 22:41, Al Whaley wrote: > > A lot of pain and suffering in this world comes from people being sure they > have a 'better idea' and everybody needs to do whatever. This feels a bit > like that. A command that gives choice and real certainty would be great. Hi, I wanted t

Deprecation notice force BIND 9.20+: "rrset-order fixed" and "sortlist"

2024-02-29 Thread Ondřej Surý
Hello, In line with ISC's deprecation policy, I am notifying the mailing list of our intent to deprecate the "sortlist" options and a value "fixed" for "rrset-order" option. These options allow to specify a on order of the resource records in the responses. The "fixed" value for "rrset-order" op