[dns-operations] Configurable TC=1?

Ralph Babel rbabel at babylon.pfm-mainz.de
Sun Dec 20 14:27:00 UTC 2015


Ralf Weber wrote:

> If we switch DNS to TCP there will be a huge cost
> in implementing this, as TCP just doesn't scale
> the way UDP does

True; so is there a nameserver implementation that
allows me to respond with a minimal TC=1 packet if ...

  sizeof(UDP-response) > sizeof(UDP-query) * x + y

..., x and y being fully configurable, preferably
on a per-address-range basis, maybe even dependent
upon the query type?

(not so much related to the "Storm on the DNS"
issue but to DNS amplification attacks)



More information about the dns-operations mailing list