Best practice on TCP replies for ANY queries
sina at redteam.io
Thu Dec 12 16:23:10 UTC 2013
The Internet will be a better place with less open resolvers around.
On Dec 12, 2013 5:32 AM, "Tony Finch" <dot at dotat.at> wrote:
> Anurag Bhatia <me at anuragbhatia.com> wrote:
> > Now I see presence of some (legitimate) DNS forwarders and hence I don't
> > wish to limit queries.
> You are going to have to change your mind about this one. Open recursive
> resolvers are a really bad idea, unless you can afford a lot of time and
> cleverness to manage the abuse. Get your users to choose a more
> appropriate name server, and restrict your name server to your local
> f.anthony.n.finch <dot at dotat.at> http://dotat.at/
> Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at
> Rough, becoming slight or moderate. Showers, rain at first. Moderate or
> occasionally poor at first.
More information about the NANOG