[dns-operations] EDNS0 client-subnet option from Google Resolvers

Daniel Stirnimann daniel.stirnimann at switch.ch
Fri Oct 23 06:31:40 UTC 2015


Hello

I was wondering why Google DNS (8.8.8.8) resolvers don't use EDNS0
client-subnet option in every request towards our authoritative name server.

The following table shows a break down of google resolvers and the
number of EDNS0 client-subnet queries vs. none client-subnet queries.

count  ,srcaddr         ,opt-code  ,opt-len
14731  ,"74.125.176.176",0         ,0
40     ,"74.125.176.176",8         ,7
14133  ,"74.125.176.177",0         ,0
28     ,"74.125.176.177",8         ,7
14382  ,"74.125.176.178",0         ,0
28     ,"74.125.176.178",8         ,7
14342  ,"74.125.176.179",0         ,0
35     ,"74.125.176.179",8         ,7
13743  ,"74.125.176.180",0         ,0
25     ,"74.125.176.180",8         ,7
15226  ,"74.125.176.181",0         ,0
31     ,"74.125.176.181",8         ,7
14331  ,"74.125.176.182",0         ,0
29     ,"74.125.176.182",8         ,7
15568  ,"74.125.176.183",0         ,0
28     ,"74.125.176.183",8         ,7

The number of queries with EDNS0 client-subnet is rather low. Is this
because the resolver figured out that our authoritative name server is
not responding this option, so they don't send it every time but just
from time to time to check if we support it now?

Daniel


-- 
SWITCH
Daniel Stirnimann, SWITCH-CERT
Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland
phone +41 44 268 15 15, direct +41 44 268 16 24
daniel.stirnimann at switch.ch, http://www.switch.ch



More information about the dns-operations mailing list