Network diversity Software diversity

Greg A. Woods woods at weird.com
Thu Jan 25 05:46:46 UTC 2001


[ On , January 24, 2001 at 17:19:29 (-0800), Sean Donelan wrote: ]
> Subject: Network diversity Software diversity
>
> Using FreeBSD and BIND on *ALL* your name servers may be just as
> bad a practice as using Windows 2000 and Microsoft DNS on *ALL*
> your name servers.  I still think NSI is taking a tremendous risk
> using identical servers for all their GTLD-servers, even though
> they are geographically distributed.

Yeah, I was going to mention that, but I thought I'd already been
preaching too much to the converted!  :-)

> You might try using UltraDNS on half your critical nameservers and
> BIND on the other half.  And even using Solaris on some of the
> boxes and AIX or Linux, or NetBSD on the others. This is not because
> I think one or the other has a fatal flaw, but because software is
> a hard beast to manage.  The idea behind diversity isn't you will
> never have an error.  But the errors are unlikely to strike both
> servers at the same time.

Therein lies the rub -- adding extra complexity to your systems also
makes them more difficult to manage, prone to error, and subject to
interoperational problems.

Diversity of all forms definitely has its advantages, but it has its
costs too.  The trick is to find a fair balance.  :-)

-- 
							Greg A. Woods

+1 416 218-0098      VE3TCP      <gwoods at acm.org>      <robohack!woods>
Planix, Inc. <woods at planix.com>; Secrets of the Weird <woods at weird.com>




More information about the NANOG mailing list