Option to turn off EDNS globally?

Mark Andrews Mark_Andrews at isc.org
Fri Sep 21 00:41:07 UTC 2007


	If you talk DNS over IPv6 you are REQUIRED to implement EDNS.
	This applies to servers and resolvers.

	EDNS is 8 years old.  If you bought your firewall/nat box
	in the last 5 years it should cope with EDNS.  There is a
	reason that RFC 2671 has Category: Standards Track on it.
	Thats given vendors 3 years to notice the RFC.  Note during
	this entire peroid named has been making EDNS requests so
	this really should be nothing new to those vendors.

	For what it is worth EDNS does not significantly slow down
	resolution when talking to RFC 1034 compliant servers.  The
	only times when things slow down significantly is when the
	remote nameserver fails to follow RFC 1034 by dropping the
	query rather than returning a error code or when middle
	boxes drop packets.  The later are usually under the control
	of the querier as very few boxes drop outgoing fragments
	or large responses.  

	Named also has seperate controls for both incoming and
	outgoing EDNS packet sizes.  It also has controls for whether
	it will initiate a EDNS query.  It also has controls so
	that the message can be filtered.

	Mark
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark_Andrews at isc.org


More information about the bind-workers mailing list