OpenDNS CGNAT Issues

Mark Andrews marka at isc.org
Wed Sep 12 03:08:20 UTC 2018



> On 11 Sep 2018, at 11:07 pm, Aled Morris via NANOG <nanog at nanog.org> wrote:
> 
> On Tue, 11 Sep 2018 at 13:56, Ca By <cb.list6 at gmail.com> wrote:
> You should provide your users ipv6, opendns supports ipv6 and likely will not have this issue you see 
> 
> OpenDNS does not support IPv6 for their customisable services "Home" etc. which I believe is the service the OP is using as he refers to the end-user wanting to register their IP address.

We really should get away from using IP addresses for identifying anything.  At the
DNS level you can use a EDNS option to identify the client rather than the IP address.
I believe their Umbrella product does this.

You can also use TSIG to identify clients independent of IP address.

We added TSIG support to libresolv right at the beginning of the century.

Mark

> Incidentally, I hope OpenDNS considers 100.64.0.0/10 as space that can't be registered to any end-user.
> 
> Aled

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka at isc.org




More information about the NANOG mailing list