ECN, DNS and Firewalls

Mark Andrews marka at isc.org
Fri Dec 28 02:35:04 UTC 2018


There are major operators that still have STUPID firewall settings
in front of DNS servers that drop SYN packets with ECE and CWR set
17 years after ECN was specified.

Do you really want to add a second to EVERY DNS lookup that needs
to use TCP?  Modern OS actually attempt to use ECN by default.  DNS
is time critical enough without introducing unnecessary delays.

If you have signed zones then TCP requests are almost certainly being
made to your servers.

EVERYONE TEST YOUR SERVERS FROM OUTSIDE YOUR NETWORK AND FIX THE BROKEN
FIREWALLS THAT ARE FOUND.

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka at isc.org




More information about the NANOG mailing list