Bluehost.com Web Hosting $6.95

Re: Are those extra/useless queries? (fwd)

This is a discussion on Re: Are those extra/useless queries? (fwd) within the Bind Users forums, part of the DNS and Related Forums category; Thanks for the answer. That makes sense. I checked the Bind8 and it already has that feature enabled. One thing ...


Go Back   Usenet Forums > DNS and Related Forums > Bind Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-03-2004
Hao Shang
 
Posts: n/a
Default Re: Are those extra/useless queries? (fwd)

Thanks for the answer. That makes sense. I checked the Bind8 and it
already has that feature enabled.

One thing need to point out is Bind9.2.3 seems not caring whether the
canonical name is from the same zone as the original query or not, it
always sends query for the cname.

e.g. query to "www.cnn.com" will return
answer with "
www.cnn.com" cname "cnn.com" and
"cnn.com" A "xxx.xxx.xxx.xxx".

Although "cnn.com" does come from the same zone as "www.cnn.com",
Bind9.2.3 will still send another query for "cnn.com". Bind8 won't though.

-------
Hao

On Tue, 2 Mar 2004, Barry Margolin wrote:

> In article <c22dj8$12v1$1@sf1.isc.org>, Hao Shang <hao@cs.wpi.edu>
> wrote:
>
> > 3) Canonical Name: In the Answer section, the first RR could be a
> > canonical name followed by RRs giving resolutions for the canonical
> > name. The strange thing is why it sends query again for the canonical
> > name even the answers are already included before.
> >
> > Is there an option to tune this behavior?
> >
> > 4) NS RRs: In the Authoritative Nameservers section of a response,
> > name server RRs for a zone are given. And resolutions for them are
> > given in the Additional Section. But I observed sometimes (not
> > always) Bind sends queries for those server names again even
> > resolutions for them are attached before.
> >
> > Is there any option to control this behavior?

>
> I think both of these are attempts to avoid cache poisoning by
> non-authoritative servers. So if the canonical name or NS record is not
> in the same zone as the name that was queried, the additional info
> cannot necessarily be trusted. The server will ask the authoritative
> server for that zone, to ensure that it has the most reliable data.
>
> --
> Barry Margolin, barmar@alum.mit.edu
> Arlington, MA
>
>



Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 12:44 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0