nanog mailing list archives

Re: Recommended DNS server for a medium 20-30k users isp


From: Nick Hilliard via NANOG <nanog () lists nanog org>
Date: Fri, 8 Aug 2025 12:05:01 +0100

Saku Ytti via NANOG wrote on 08/08/2025 10:23:
Eventually you will manage to cause an issue, where all advertisements
are falsely pulled.

Someone up-thread mentioned firewalling DNS servers.

Withdrawing DNS service workers due to firewall state overloading can cause cascading service failure which can take out an entire DNS infrastructure within milliseconds. Don't ask me how I know this.

Also obviously works when n=1.

tl;dr: packet filters only for DNS, preferably in hardware. Don't ever use state tracking.

Nick
_______________________________________________
NANOG mailing list https://lists.nanog.org/archives/list/nanog () lists nanog org/message/UGOKLG42SE3GHENKGQMMO63RZ5GWOTM6/


Current thread: