[dns-operations] DNS reflection useful without amplification? (was: if you're banning ANY queries, don't forget to ban SOA as well)

Roland Dobbins rdobbins at arbor.net
Wed Sep 7 11:10:17 UTC 2016


On 7 Sep 2016, at 14:37, Mark Andrews wrote:

> Reflection requires more time to trace back to the source.  You have to
> trace from the target to the reflector then from the reflector to the
> initiator.
>
> Reflection increases the number of streams that need to be chased back.

+1

-----------------------------------
Roland Dobbins <rdobbins at arbor.net>



More information about the dns-operations mailing list