Paul Vixie: Re: [dns-operations] DNS issue accidentally leaked?

michael.dillon at michael.dillon at
Thu Jul 24 13:57:59 UTC 2008

> So, look at other options:
> * Widen the query space by using multiple IP addresses as 
> source.  This,
>   of course, has all the problems with NAT gw's that the port solution
>   did, except worse.
>   This makes using your ISP's "properly designed" resolver even more
>   attractive, rather than running a local recurser on your company's
>   /28 of public IP space, but has the unintended consequence of making
>   those ISP recursers even more valuable targets.
> Makes you wish for wide deployment of IPv6, eh.

> The only real fix I see is to deploy DNSSEC.

You seem to be saying, above, that IPv6 is also a real fix, presumably
because it allows for the 64-bit host id portion of an IP address to
"fast flux". Or have I misunderstood?

It would be nice for someone to explain how (or if) IPv6 changes this
situation since many networks are already well into the planning stages
for IPv6 deployment within the next two to three years. 

--Michael Dillon

