Option to turn off EDNS globally?
Mark Andrews
Mark_Andrews at isc.org
Fri Sep 21 00:41:07 UTC 2007
If you talk DNS over IPv6 you are REQUIRED to implement EDNS.
This applies to servers and resolvers.
EDNS is 8 years old. If you bought your firewall/nat box
in the last 5 years it should cope with EDNS. There is a
reason that RFC 2671 has Category: Standards Track on it.
Thats given vendors 3 years to notice the RFC. Note during
this entire peroid named has been making EDNS requests so
this really should be nothing new to those vendors.
For what it is worth EDNS does not significantly slow down
resolution when talking to RFC 1034 compliant servers. The
only times when things slow down significantly is when the
remote nameserver fails to follow RFC 1034 by dropping the
query rather than returning a error code or when middle
boxes drop packets. The later are usually under the control
of the querier as very few boxes drop outgoing fragments
or large responses.
Named also has seperate controls for both incoming and
outgoing EDNS packet sizes. It also has controls for whether
it will initiate a EDNS query. It also has controls so
that the message can be filtered.
Mark
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: Mark_Andrews at isc.org
More information about the bind-workers
mailing list